CVE-2025-58757: Monai Medical Open Network For Ai

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. In versions up to and including 1.5.0, the `pickle_operations` function in `monai/data/utils.py` automatically handles dictionary key-value pairs ending with a specific suffix and deserializes them using `pickle.loads()` . This function also lacks any security measures. The deserialization may lead to code execution. As of time of publication, no known fixed versions are available.

Affected products

  • Monai Medical Open Network For Ai: up to and including 1.5.0

Published 2025-09-09. Last modified 2026-06-17.