#MonAi
vc não cansa né monai KKKKKKKK
October 6, 2026 at 2:36 PM
Dnv me identifiquei com a monai
Sinceramente? To me esforçando pra que nessa porra?
October 5, 2026 at 9:40 AM
Cara agora vou imaginar a monai como zara
October 4, 2026 at 5:25 PM
Quem lembra da Monai dessa época?
October 4, 2026 at 3:01 AM
【脆弱性情報】 [Python]
Project-monaiのMONAIにおけるEval インジェクションに関する脆弱性

公開日: 2026-10-02T14:56:34+09:00
詳細: https://jvndb.jvn.jp/ja/contents/2026/JVNDB-2026-036184.html
October 2, 2026 at 10:00 PM
📌 CVE-2026-100843 - MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserializat... https://www.potatohub.blog/cves/CVE-2026-100843
October 1, 2026 at 11:37 PM
📌 CVE-2026-100843 - MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserializat... https://www.cyberhub.blog/cves/CVE-2026-100843
CVE-2026-100843
MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pickle.loads() deserialization in monai/auto3dseg/utils.py. Attackers can craft malicious pickle files that execute arbitrary system commands when deserialized by the vulnerable
www.cyberhub.blog
October 1, 2026 at 11:37 PM
📌 CVE-2026-100841 - In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who... https://www.cyberhub.blog/cves/CVE-2026-100841
CVE-2026-100841
In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_only=True, forcing users who cache MetaTensors (the default tensor type in MONAI >= 1.0) to run torch.load(hashfile, weights_only=False). Related cache helpers in monai/data/util
www.cyberhub.blog
October 1, 2026 at 11:07 PM
📌 CVE-2026-100840 - MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary impor... https://www.cyberhub.blog/cves/CVE-2026-100840
CVE-2026-100840
MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary importable callables without an allow list and passes $ expressions to Python eval(). Attackers can publish a malicious bundle with crafted configuration c
www.cyberhub.blog
October 1, 2026 at 10:37 PM
📌 CVE-2026-100845 - MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=Tr... https://www.cyberhub.blog/cves/CVE-2026-100845
CVE-2026-100845
MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.load with allow_pickle=True when loading .npy and .npz files. Attackers can craft malicious .npy files with pickle payloads that execute arbitrary code when loaded through MON
www.cyberhub.blog
October 1, 2026 at 10:07 PM
📌 CVE-2026-100844 - MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values t... https://www.cyberhub.blog/cves/CVE-2026-100844
CVE-2026-100844
MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments are concatenated into a command string without quotin
www.cyberhub.blog
October 1, 2026 at 9:37 PM
📌 CVE-2026-100846 - MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The functi... https://www.potatohub.blog/cves/CVE-2026-100846
October 1, 2026 at 8:37 PM
📌 CVE-2026-100846 - MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The functi... https://www.cyberhub.blog/cves/CVE-2026-100846
CVE-2026-100846
MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3dseg/utils.py. The function reads a .pkl file and passes its contents to pickle.loads without validating the data source or content. If an application invokes algo_from_pickle
www.cyberhub.blog
October 1, 2026 at 8:37 PM
Medical images can contain patient identifiers in both their metadata & visible pixels. Here, Lakshmi shows you how to build an AI-powered de-identification pipeline for clinical research. You'll use MONAI, OCR, and NER to detect and remove sensitive info.
www.freecodecamp.org/news/build-a...
September 29, 2026 at 8:01 PM
Sinto muito monai. Espero que vc fique bem
September 28, 2026 at 1:35 AM
🟠 CVE-2026-100844 - High (8.4)

MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.a...

https://www.thehackerwire.com/vulnerability/CVE-2026-100844/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 12:46 AM
🟠 CVE-2026-100843 - High (7.8)

MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle...

https://www.thehackerwire.com/vulnerability/CVE-2026-100843/

#infosec #cybersecurity #CVE #vulnerability #security #patchstack
September 28, 2026 at 12:46 AM
Breaking: High-Severity MONAI Flaw Lets Local Users Run Code via Poisoned Pickle Cache. That, plus 2 more — the day's biggest tech stories, fact-checked and cut to two minutes.
September 27, 2026 at 9:13 PM
CVE-2026-100841: high-severity flaw in MONAI (all versions through 1.6.0).

• PersistentDataset forces unsafe torch.load on cached MetaTensors
• Local user who can write to a shared cache can run code

https://thecircuitry.to/article/monai-160-hit-by-high-severity-rce-flaw-via-pickle-cache-muk13d8j
September 27, 2026 at 6:58 PM
Gostosa dessa sofrendo, pare com isso Monai
September 27, 2026 at 2:57 PM
🚨 EUVD-2026-87848
📊 8.5/10
🏢 Project-MONAI

📝 MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary imp...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87848

#cybersecurity #infosec #cve #euvd
September 27, 2026 at 3:03 AM