Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-100843

MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system commands when deserialized by the vulnerable function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 7.6%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2026-100843


Contact Us

Shodan ® - All rights reserved