Junglewise Threat Intelligence

CVE-2026-100844: MONAI OS command injection in nnUNetV2Runner

CVE-2026-100844 · Severity: high · CVSS 8.4 · Published 2026-09-27

Technologies: Project-MONAI MONAI. Vendors: Project-MONAI.

Executive brief

MONAI is a deep learning framework used for medical image analysis and training neural network models. A vulnerability in its nnUNetV2Runner component allows attackers to execute arbitrary operating system commands by injecting shell metacharacters into configuration files or command-line arguments. An attacker who tricks a user into loading a malicious YAML configuration file can gain full control of the system with the privileges of the user running the training job.

Technical details

OS command injection in nnUNetV2Runner via unsanitized user input (dataset_name_or_id from YAML config or CLI/kwargs arguments) concatenated into shell commands and executed with subprocess shell=True. Attack vector is local; user must load a crafted YAML configuration file and invoke training/validation functions (e.g., train_single_model()). No privileges or network access required; arbitrary code execution with user privileges.

Affected products

  • Project-MONAI MONAI before 1.6.0

Timeline

  • 2026-09-27: disclosed
  • 2026-06-11: patched: Version 1.6.0 released with patch

References

Related threats