CVE-2026-100841

LOWCVSS 8.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). Related cache helpers in monai/data/utils.py also call pickle.loads on cached content and derive cache keys with hashlib.md5. As a result, a local user with write access to a shared or world-writable cache_dir (e.g. /tmp/monai_cache, HPC scratch, ~/.cache/monai) can place a malicious pickle file that is deserialized the next time another user's MONAI pipeline reads the cache, resulting in arbitrary code execution in that user's context. All released versions of the monai pip package are affected; no patched version is available as of the advisory.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-27: 209-27
Referenced assets2 URLs
Full discourse2 posts
  • Severity Daily@severitydaily

    To cache MetaTensors, MONAI's error message tells you to switch off PyTorch's weights_only guard. Today's CVE says no fix exists; the fix shipped nine days ago in a release candidate. No exploitation reported. https://severitydaily.com/monai-cve-2026-100841-patched-none-fixed-1-6-1rc0-release-candidate/

    0000026
    25 followersView on X
  • The Circuitry@thecircuitry_

    CVE-2026-100841: high-severity flaw in MONAI (all versions through 1.6.0). • PersistentDataset forces unsafe torch.load on cached MetaTensors • Local user who can write to a shared cache can run code • CVSS 8.5, no stable patch yet https://thecircuitry.to/article/monai-160-hit-by-high-severity-rce-flaw-via-pickle-cache-muk13d8j

    0000039
    37 followersView on X

Explore more