CVE-2025-58757

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function in `monai/data/utils.py` automatically handles dictionary key-value pairs ending with a specific suffix and deserializes them using `pickle.loads()` . This function also lacks any security measures. The deserialization may lead to code execution. As of time of publication, no known fixed versions are available.
Configurations

No configuration.

History

09 Sep 2025, 14:15

Type Values Removed Values Added
References () https://github.com/Project-MONAI/MONAI/security/advisories/GHSA-p8cm-mm2v-gwjm - () https://github.com/Project-MONAI/MONAI/security/advisories/GHSA-p8cm-mm2v-gwjm -

09 Sep 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-09 00:15

Updated : 2025-09-09 16:28


NVD link : CVE-2025-58757

Mitre link : CVE-2025-58757

CVE.ORG link : CVE-2025-58757


JSON object : View

Products Affected

No product.

CWE
CWE-502

Deserialization of Untrusted Data