Skip to content
CVE Alert: CVE-2026-100844 – Project-MONAI

CVE Alert: CVE-2026-100844 – Project-MONAI

Redpacketsecurity •admin • September 27, 2026

MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments are concatenated into a command string without quoting or validation and then passed to subprocess with shell=True, so shell metacharacters (e.g., ‘;’ on Linux, ‘&’ on Windows) are interpreted. If a victim loads and processes a crafted configuration file — for example by instantiating nnUNetV2Runner with the malicious YAML and invoking a training/validation job such as train_single_model() — arbitrary commands are executed with the privileges of the user running the job.

This is a high-impact local code-execution risk; urgency cannot be confirmed without KEV, SSVC exploitation, PoC and EPSS data.

Successful exploitation can give an attacker the same access as the job-running account, enabling data theft, model or dataset tampering, and disruption of research or clinical AI workflows. The practical risk is greatest where untrusted configuration files enter automated processing pipelines.

### Most likely attack path

An attacker places a crafted configuration where a user or service will load it, and the vulnerable runner processes it; the stated metrics indicate low technical barriers and no required privileges or interactive action. Scope is unchanged, so the flaw does not itself cross a security boundary, but an attacker may use the compromised account’s existing access to reach data, credentials or systems.

### Who is most exposed

Prioritise teams running medical-imaging AI workflows, especially shared research environments and automated training or validation services that ingest externally supplied configurations.

Review job logs for unexpected shell errors or commands during runner execution.

Hunt process telemetry for shell or utility processes spawned by Python training jobs.

Inspect configuration provenance and audit unusual changes to dataset identifiers or CLI arguments.

### Mitigation and prioritisation

Upgrade to the vendor-fixed release; verify deployed environments, notebooks and build images.

Until upgraded, reject untrusted configuration and argument values; avoid invoking affected workflows with externally supplied inputs.

Run jobs with least privilege and isolate them from sensitive credentials, shared storage and production networks.

Test the upgrade in representative workflows before broad rollout; prioritise exposed shared runners.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Platforms (2)