Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. monai
  4. ›
  5. GHSA-qxq5-qhx6-94qw

GHSA-qxq5-qhx6-94qw: Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

August 18, 2026

GHSA-89gg-p5r5-q6r4 claims the pickle deserialization vulnerability in algo_from_pickle() was fixed in v1.5.2. However, monai/auto3dseg/utils.py has not been modified since 2024-07-12 — 18 months before v1.5.2 was released (2026-01-29). All three pickle.loads() calls remain unchanged. The fix was never implemented.

References

  • github.com/Project-MONAI/MONAI/releases/tag/1.6.0
  • github.com/Project-MONAI/MONAI/security/advisories/GHSA-qxq5-qhx6-94qw
  • github.com/advisories/GHSA-89gg-p5r5-q6r4
  • github.com/advisories/GHSA-qxq5-qhx6-94qw

Code Behaviors & Features

Detect and mitigate GHSA-qxq5-qhx6-94qw with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.6.0

Fixed versions

  • 1.6.0

Solution

Upgrade to version 1.6.0 or above.

Impact 7.8 HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-502: Deserialization of Untrusted Data

Source file

pypi/monai/GHSA-qxq5-qhx6-94qw.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 10 Sep 2026 00:17:35 +0000.