PT-2026-99464 · Monai · Monai

CVE-2026-100844

·

Published

2026-08-18

·

Updated

2026-09-27

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MONAI versions prior to 1.6.0
Description OS command injection is possible in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2 runner). User-controlled values from CLI/kwargs arguments and YAML configuration files, specifically the dataset name or id variable, are concatenated into a command string without validation or quoting. This string is then passed to a subprocess with shell=True, allowing shell metacharacters to be interpreted. An attacker can execute arbitrary commands with the privileges of the user running the job by providing a crafted configuration file and invoking a training or validation job, such as the train single model() function.
Recommendations Update to version 1.6.0 or later. As a temporary mitigation, avoid using the train single model() function with untrusted YAML configuration files or unvalidated dataset name or id values.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100844
GHSA-RGHG-Q7WP-9767

Affected Products

Monai