<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 21:27:41 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-21851 — MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-21851</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Project-MONAI MONAI&lt;/p&gt;
&lt;p&gt;MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.1, a Path Traversal (Zip Slip) vulnerability exists in MONAI&amp;#39;s `_download_from_ngc_private()` function. The function uses `zipfile.ZipFile.extractall()` without path validation, while other similar download functions in the same codebase properly use the existing `safe_extract_member()` function. Commit 4014c8475626f20f158921ae0cf98ed259ae4d59 fixes this issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Project-MONAI MONAI&lt;/p&gt;
&lt;p&gt;MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.1, a Path Traversal (Zip Slip) vulnerability exists in MONAI&amp;#39;s `_download_from_ngc_private()` function. The function uses `zipfile.ZipFile.extractall()` without path validation, while other similar download functions in the same codebase properly use the existing `safe_extract_member()` function. Commit 4014c8475626f20f158921ae0cf98ed259ae4d59 fixes this issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-21851</guid>
    </item>
    <item>
      <title>GHSA-9rg3-9pvr-6p27 — MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9rg3-9pvr-6p27</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: monai&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A **Path Traversal (Zip Slip)** vulnerability exists in MONAI&amp;#39;s `_download_from_ngc_private()` function. The function uses `zipfile.ZipFile.extractall()` without path validation, while other similar download functions in the same codebase properly use the existing `safe_extract_member()` function.&lt;/p&gt;
&lt;p&gt;This appears to be an implementation oversight, as safe extraction is already implemented and used elsewhere in MONAI.&lt;/p&gt;
&lt;p&gt;**CWE:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Vulnerable Code Location&lt;/p&gt;
&lt;p&gt;**File:** `monai/bundle/scripts.py`  
**Lines:** 291-292  
**Function:** `_download_from_ngc_private()`&lt;/p&gt;
&lt;p&gt;```python
# monai/bundle/scripts.py - Lines 284-293
zip_path = download_path / f&amp;#34;{filename}_v{version}.zip&amp;#34;
with open(zip_path, &amp;#34;wb&amp;#34;) as f:
    f.write(response.content)
logger.info(f&amp;#34;Downloading: {zip_path}.&amp;#34;)
if remove_prefix:
    filename = _remove_ngc_prefix(filename, prefix=remove_prefix)
extract_path = download_path / f&amp;#34;{filename}&amp;#34;
with zipfile.ZipFile(zip_path, &amp;#34;r&amp;#34;) as z:
    z.extractall(extract_path)  # &amp;lt;-- No path validation
    logger.info(f&amp;#34;Writing into directory: {extract_path}.&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;The code calls `z.extractall(extract_path)` directly without validating that archive member paths stay within the extraction directory.&lt;/p&gt;
&lt;p&gt;### Safe Code Already Exists&lt;/p&gt;
&lt;p&gt;MONAI already has a safe extraction function in `monai/apps/utils.py` (lines 125-154) that properly validates paths:&lt;/p&gt;
&lt;p&gt;```python
def safe_extract_memb…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: monai&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A **Path Traversal (Zip Slip)** vulnerability exists in MONAI&amp;#39;s `_download_from_ngc_private()` function. The function uses `zipfile.ZipFile.extractall()` without path validation, while other similar download functions in the same codebase properly use the existing `safe_extract_member()` function.&lt;/p&gt;
&lt;p&gt;This appears to be an implementation oversight, as safe extraction is already implemented and used elsewhere in MONAI.&lt;/p&gt;
&lt;p&gt;**CWE:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory)&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Vulnerable Code Location&lt;/p&gt;
&lt;p&gt;**File:** `monai/bundle/scripts.py`  
**Lines:** 291-292  
**Function:** `_download_from_ngc_private()`&lt;/p&gt;
&lt;p&gt;```python
# monai/bundle/scripts.py - Lines 284-293
zip_path = download_path / f&amp;#34;{filename}_v{version}.zip&amp;#34;
with open(zip_path, &amp;#34;wb&amp;#34;) as f:
    f.write(response.content)
logger.info(f&amp;#34;Downloading: {zip_path}.&amp;#34;)
if remove_prefix:
    filename = _remove_ngc_prefix(filename, prefix=remove_prefix)
extract_path = download_path / f&amp;#34;{filename}&amp;#34;
with zipfile.ZipFile(zip_path, &amp;#34;r&amp;#34;) as z:
    z.extractall(extract_path)  # &amp;lt;-- No path validation
    logger.info(f&amp;#34;Writing into directory: {extract_path}.&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;The code calls `z.extractall(extract_path)` directly without validating that archive member paths stay within the extraction directory.&lt;/p&gt;
&lt;p&gt;### Safe Code Already Exists&lt;/p&gt;
&lt;p&gt;MONAI already has a safe extraction function in `monai/apps/utils.py` (lines 125-154) that properly validates paths:&lt;/p&gt;
&lt;p&gt;```python
def safe_extract_memb…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9rg3-9pvr-6p27</guid>
    </item>
  </channel>
</rss>
