The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Verified against the NVD record for CVE-2026-100841 (VulnCheck CNA, published 2026-09-27 02:17 UTC), GHSA-636w-j999-g7x5 (published 2026-08-21, patched versions: none), the VulnCheck advisory, and MONAI source at tags 1.6.0 and 1.6.1rc0. Affected <=1.6.0, CWE-502, CVSS 4.0 8.5 HIGH / 3.1 7.8 HIGH, local vector. Earlier [title-claim] "Pickle Cache" flag was a Title Case phrase false positive.

Sourcing
1source

via NVD

NVD · track record
49Stories
100%Verified
2630d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/High-Severity MONAI Flaw Lets Local Users Run Code via Poisoned Pickle Cache
VERIFIEDBy Xavier Rivera· ·1.5 min read

High-Severity MONAI Flaw Lets Local Users Run Code via Poisoned Pickle Cache

CVE-2026-100841 affects every release of the MONAI medical imaging AI framework through 1.6.0. A local user who can write to a shared cache directory can plant a malicious pickle file that runs code in another user's pipeline. It is rated high severity and no stable fix has shipped.

Source:NVD
Post
High-Severity MONAI Flaw Lets Local Users Run Code via Poisoned Pickle Cache
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

CVE-2026-100841 affects all MONAI releases through 1.6.0. PersistentDataset forces users who cache MetaTensors to load cache files with torch.load(weights_only=False), so a local user with write access to a shared cache directory can plant a malicious pickle file that executes code in another user's context. VulnCheck scores it 8.5 (CVSS 4.0) and 7.8 (CVSS 3.1), both high. The advisory lists no patched version.

A newly published vulnerability, CVE-2026-100841, affects MONAI, the open-source PyTorch framework for medical imaging AI. Every release of the monai pip package through version 1.6.0 is affected.

The flaw is in how PersistentDataset reads its pickle cache.

In MONAI 1.6.0, PersistentDataset in monai/data/dataset.py rejects the combination of track_meta=True and weights_only=True. Users who cache MetaTensors, the default tensor type since MONAI 1.0, are therefore forced to load cached files with torch.load and weights_only=False, which unpickles whatever sits in the cache directory. The advisory also flags cache helpers in monai/data/utils.py that call pickle.loads on cached content and derive cache keys with MD5.
A local user with write access to a shared or world-writable cache_dir can place a malicious pickle file that is deserialized the next time another user's MONAI pipeline reads the cache.

An attacker needs local write access to a shared cache.

A local user who can write to a shared or world-writable cache_dir, such as /tmp/monai_cache, HPC scratch space or ~/.cache/monai, can plant a malicious file there, creating a poisoned pickle cache. The next time another user's MONAI pipeline reads the cache, the file is deserialized, letting the attacker run code in that user's context. The attack vector is local, and MONAI's advisory describes it as a privilege-escalation risk on shared HPC clusters.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →

It is rated high severity.

VulnCheck, which assigned the CVE, scores it 8.5 under CVSS 4.0 and 7.8 under CVSS 3.1, both high. The scores reflect low attack complexity, low privileges required, no user interaction and high impact to confidentiality, integrity and availability. MONAI's own GitHub advisory, GHSA-636w-j999-g7x5, published on August 21, also rates it high at 7.8.

No stable fix has shipped.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
The advisory lists no patched version, and the NVD entry, published on September 26, says all released versions are affected. The 1.6.1 release candidate tagged on September 18 changes this code: PersistentDataset no longer blocks MetaTensor caching with weights_only=True, and cache keys use SHA-256 instead of MD5. It is not yet a stable release. Until one lands, teams should avoid shared or world-writable cache directories; the advisory's recommended fix includes creating cache folders with owner-only 0700 permissions.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
securityvulnerabilitymonai
More fromNVD
  • Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Tech · 12h
  • Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    Tech · 12h
  • Critical CVE-2026-88131 hits Microsoft Dataverse with remote code execution

    Tech · 12h
More inTech
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 9h
  • SpaceX agrees to buy 800 MHz spectrum for Starlink Mobile

    Tech · 12h
  • Anthropic Launches Cyber Mission to Secure Infrastructure and Open-Source Code

    Tech · 15h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.

  • Tech· 

    Critical CVE-2026-77900 Hits Microsoft Azure App Service for Linux

    A critical vulnerability CVE-2026-77900 affects Microsoft Azure App Service for Linux with a CVSS score of 9.8. The flaw allows an unauthenticated attacker to execute code over the network. Microsoft says it has already fully mitigated the flaw; no customer action is needed.

  • Tech· 

    Critical CVE-2026-88131 hits Microsoft Dataverse with remote code execution

    Microsoft Dataverse is affected by critical vulnerability CVE-2026-88131, which allows remote code execution. The flaw scores 9.8 on CVSS; Microsoft says it has already fully mitigated it and customers have nothing to patch.

  • Tech· 

    Critical CVE-2026-16823 hits IBM Security Verify Access

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 contain critical authentication bypass flaw CVE-2026-16823. The NVD rates it 9.1 and warns of remote exploitation without credentials.

  • Tech· 

    Red Hat OpenShift 4 hit by CVE-2026-93017 with 7.7 CVSS score

    Red Hat OpenShift Container Platform 4 is affected by CVE-2026-93017, a high-severity flaw that lets attackers read every secret in every namespace. The 7.7 CVSS score reflects broad access granted through an unrestricted ClusterRole on the insights-operator-gather service account.