PatchSiren

Project-MONAI CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Project-MONAI CVE published 2026-09-27

CVE-2026-100841

A local user can exploit a malicious pickle file in a shared MONAI cache directory, leading to arbitrary code execution in another user's context when their MONAI pipeline reads the cache. This vulnerability affects MONAI 1.6.0 and allows for potential lateral movement and privilege escalation. System administrators and MONAI users should assess their exposure and take remediation steps to verify cache di [truncated]