MONAI (Medical Open Network for AI) versions up to and including 1.5.1 contain a path traversal (Zip Slip) vulnerability in the _download_from_ngc_private() function. The vulnerable code uses Python’s zipfile.ZipFile.extractall() to extract an attacker-influenced ZIP archive without validating member paths, allowing archive entries with ../ sequences or absolute paths to escape the intended extraction directory. Other similar download paths in the codebase use MONAI’s existing safe_extract_member() helper, but _download_from_ngc_private() did not. The issue is fixed by commit 4014c8475626f20f158921ae0cf98ed259ae4d59, which replaces unsafe extraction with MONAI’s safe extraction logic.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
source="ngc_private" and restrict that workflow. Enforce strict access control and monitoring on NGC private repositories to prevent attacker-controlled bundle uploads. Run MONAI with least privilege and in a constrained environment (e.g., containerization, minimized filesystem write access, read-only filesystem where feasible) to reduce the impact of arbitrary file writes.Patch, then assume compromise.
4014c8475626f20f158921ae0cf98ed259ae4d59. Ensure _download_from_ngc_private() no longer calls zipfile.ZipFile.extractall() directly and instead uses MONAI’s safe extraction routine (e.g., _extract_zip / safe_extract_member) that enforces extraction-root containment for all archive members.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains two Python scripts and two Markdown reports centered on CVE-2026-21847, a claimed hardcoded AES key exposure in the DPDC subscription portal JavaScript bundle. The main code files are `cve_poc_simple.py`, a lightweight demonstrator that downloads `https://subscription.dpdatacenter.com/js/app.1773634386574.js`, checks for a known embedded key, prints exposed localStorage keys, and lists internal API routes; and `dpdccve_scanner.py`, a larger scanner/reporting tool with CLI options for subdomain enumeration, key extraction, and report generation. The exploit capability is not a memory corruption or RCE payload; instead it is a web/browser token-compromise workflow: identify the hardcoded client-side AES key, use it to decrypt browser-stored authentication tokens, then reuse those tokens against DPDC API endpoints for unauthorized access. The repository also documents related infrastructure such as `subscription.dpdatacenter.com`, `api.dpdatacenter.com`, `web.dpdatacenter.com`, and `web2.dpdatacenter.com`, plus several API paths including `/customer/information`, `/vm-instances/reboot-vm`, and `/whmcpanel/get-bulk-account-summary`. Overall, this is an operational PoC/scanner for credential/token abuse against a web application with client-side cryptographic key exposure, not just a README or pure detector.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.