OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100842

HIGH · CVSS 7 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

MONAI versions up to 1.6.0 are vulnerable to an eval injection flaw in the _get_fake_spatial_shape() function, allowing attackers to bypass validation and execute arbitrary code through crafted bundle metadata. This vulnerability poses a significant risk, as it enables code execution in contexts that could compromise system integrity. Organizations utilizing MONAI for medical imaging or AI applications should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100842
Severity
HIGH
CVSS
7
EPSS
0.15%

Original NVD Description

MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The function validates shape expressions with a helper that walks the AST and only collects ast.Name nodes, rejecting any name other than 'p' or 'n', before passing the string to eval(). Expressions built solely from constants and attribute, subscript, or call nodes (for example "(1).__class__.__bases__[0].__subclasses__()" or "int.__class__.__init__.__globals__") contain no ast.Name nodes and therefore bypass the allowlist. Because the shape value originates from bundle metadata consumed by _get_real_input_data and verify_net_in_out (reachable through the bundle 'verify_net_in_out' CLI flow), an attacker who can influence a bundle's metadata can escape the eval sandbox via object introspection chains and achieve code execution in this non-default flow.

Related CVEs

Other vulnerabilities affecting the same vendor(s)