Sceawere
Vulnerability Detail
CVE-2026-100844UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MONAI OS Command Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.4
- Creation Date
- 1d ago
- Vendor
- Project-MONAI
- Product
- MONAI
- Attack Type
- Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments are concatenated into a command string without quoting or validation and then passed to subprocess with shell=True, so shell metacharacters (e.g., ';' on Linux, '&' on Windows) are interpreted. If a victim loads and processes a crafted configuration file — for example by instantiating nnUNetV2Runner with the malicious YAML and invoking a training/validation job such as train_single_model() — arbitrary commands are executed with the privileges of the user running the job.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.4",
"pubDate": "2026-09-27T02:17:22.993Z",
"pubdate": "2026-09-27T02:17:22.993Z",
"executiveSummary": "A critical OS command injection vulnerability exists within the nnUNetV2Runner component of the MONAI framework prior to version 1.6.0. The flaw arises from insecure handling of user-controlled inputs during the construction of system commands.\nBy supplying a maliciously crafted YAML configuration file or manipulating CLI/kwargs arguments, an attacker can inject arbitrary shell metacharacters. This vulnerability leads to the execution of unintended commands with the privileges of the application process.\nThe risk is significant, as it enables full command execution if a victim processes a compromised configuration. Successful exploitation requires an attacker to convince a user to load a malicious configuration or provide malicious input parameters. The vulnerability impacts all MONAI deployments using affected versions of the nnUNetV2Runner, potentially leading to unauthorized data access, system manipulation, or further lateral movement within the host environment.",
"technicalDetails": "The vulnerability originates in the monai.apps.nnunet.nnunetv2_runner component, which fails to properly sanitize or parameterize input data before executing system-level operations. Specifically, the nnUNetV2Runner class takes various parameters, such as 'dataset_name_or_id', directly from YAML configuration files or CLI/kwargs arguments.\nThese inputs are concatenated directly into a command string intended for execution via Python's subprocess module with the 'shell=True' parameter. Because the framework does not implement rigorous validation or quoting for these inputs, the underlying shell interprets embedded metacharacters, such as ';' on Linux or '&' on Windows systems.\nThe attack flow begins when an attacker creates a malicious YAML configuration file containing an injected command payload within fields like 'dataset_name_or_id'. When a victim invokes methods such as 'train_single_model()' using this crafted file, the application processes the input and assembles the command string. Upon reaching the execution phase, the 'subprocess' call interprets the injected shell sequence, triggering the payload alongside the intended nnUNet command.\nNo authentication or specific network exposure is inherently required for exploitation; the primary vector is the ingestion of untrusted data by the library. The impact is severe, as the arbitrary commands execute with the full privileges of the user account running the MONAI job. This allows for post-exploitation activities including, but not limited to, unauthorized file read/write, credential exfiltration, and full system compromise if the MONAI process runs with elevated permissions.\nThis vulnerability persists across all versions of MONAI prior to 1.6.0. The reliance on 'shell=True' in conjunction with unvalidated input concatenation remains the primary root cause, bypassing expected input normalization and safe command construction practices."
}