Remote Code Execution Vulnerability in MONAI Product from Project MONAI
CVE-2026-100840
8.5HIGH
What is CVE-2026-100840?
The MONAI framework, up to version 1.6.0, is susceptible to a remote code execution vulnerability introduced through its bundle configuration engine. This flaw allows malicious actors to craft bundles that can execute arbitrary code by leveraging unresolved target values, bypassing security measures such as an allow list. The vulnerability arises as the system improperly processes $ expressions through Python's eval() function when the bundle is loaded or executed. Users are advised to update to the latest version and review security practices to mitigate the risks associated with this vulnerability.
Affected Version(s)
MONAI 0 <= 1.6.0
