<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:27:49.748649+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-21851</id>
    <title>CVE-2026-21851 — MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download</title>
    <updated>2026-10-04T21:27:49.750282+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Project-MONAI MONAI</p>
<p>MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.1, a Path Traversal (Zip Slip) vulnerability exists in MONAI's `_download_from_ngc_private()` function. The function uses `zipfile.ZipFile.extractall()` without path validation, while other similar download functions in the same codebase properly use the existing `safe_extract_member()` function. Commit 4014c8475626f20f158921ae0cf98ed259ae4d59 fixes this issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-21851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9rg3-9pvr-6p27</id>
    <title>GHSA-9rg3-9pvr-6p27 — MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download</title>
    <updated>2026-10-04T21:27:49.750339+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: monai</p>
<p>## Summary</p>
<p>A **Path Traversal (Zip Slip)** vulnerability exists in MONAI's `_download_from_ngc_private()` function. The function uses `zipfile.ZipFile.extractall()` without path validation, while other similar download functions in the same codebase properly use the existing `safe_extract_member()` function.</p>
<p>This appears to be an implementation oversight, as safe extraction is already implemented and used elsewhere in MONAI.</p>
<p>**CWE:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory)</p>
<p>---</p>
<p>## Details</p>
<p>### Vulnerable Code Location</p>
<p>**File:** `monai/bundle/scripts.py`  
**Lines:** 291-292  
**Function:** `_download_from_ngc_private()`</p>
<p>```python
# monai/bundle/scripts.py - Lines 284-293
zip_path = download_path / f"{filename}_v{version}.zip"
with open(zip_path, "wb") as f:
    f.write(response.content)
logger.info(f"Downloading: {zip_path}.")
if remove_prefix:
    filename = _remove_ngc_prefix(filename, prefix=remove_prefix)
extract_path = download_path / f"{filename}"
with zipfile.ZipFile(zip_path, "r") as z:
    z.extractall(extract_path)  # &lt;-- No path validation
    logger.info(f"Writing into directory: {extract_path}.")
```</p>
<p>### Root Cause</p>
<p>The code calls `z.extractall(extract_path)` directly without validating that archive member paths stay within the extraction directory.</p>
<p>### Safe Code Already Exists</p>
<p>MONAI already has a safe extraction function in `monai/apps/utils.py` (lines 125-154) that properly validates paths:</p>
<p>```python
def safe_extract_memb…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9rg3-9pvr-6p27"/>
  </entry>
</feed>
