OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100845

HIGH · CVSS 7.8 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

MONAI versions prior to 1.6.0 are vulnerable due to an unsafe deserialization flaw in the NumpyReader class, which allows the use of numpy.load with allow_pickle=True. This vulnerability enables attackers to create malicious .npy files that can execute arbitrary code when processed through MONAI's data pipeline. Organizations utilizing MONAI for data handling should prioritize patching to mitigate the risk of code execution attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100845
Severity
HIGH
CVSS
7.8
EPSS
0.14%

Original NVD Description

MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payloads that execute arbitrary code when loaded through MONAI's standard data pipeline.

Related CVEs

Other vulnerabilities affecting the same vendor(s)