CVE-2025-58755
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
09/09/2025
Last modified:
19/09/2025
Description
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used directly to process compressed files. It is used in many places in the project. In versions up to and including 1.5.0, when the Zip file containing malicious content is decompressed, it overwrites the system files. In addition, the project allows the download of the zip content through the link, which increases the scope of exploitation of this vulnerability. As of time of publication, no known fixed versions are available.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:monai:medical_open_network_for_ai:*:*:*:*:*:*:*:* | 1.5.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



