在 MONAI 1.6.0 之前的版本中,nnUNetV2Runner 组件(monai.apps.nnunet.nnunetv2_runner)存在操作系统命令注入漏洞。攻击者可以利用来自 YAML 配置文件(特别是 dataset_name_or_id 字段)以及命令行参数或 kwargs 参数中的用户可控值,这些值在被拼接成命令字符串时,未经过任何引用或验证处理,随后以 shell=True 的方式传递给 subprocess 模块执行,导致 Shell 元字符(例如 Linux 上的“;”和 Windows
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Project-MONAI | MONAI | 0 ~ 1.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100841 | 7.8 HIGH | MONAI through 1.6.0 PersistentDataset Remote Code Execution via Pickle Cache |
| CVE-2026-100843 | 7.8 HIGH | MONAI before 1.6.0 Remote Code Execution via algo_from_pickle |
| CVE-2026-100845 | 7.8 HIGH | MONAI before 1.6.0 Remote Code Execution via NumpyReader |
| CVE-2026-100840 | 7.8 HIGH | MONAI through 1.6.0 Remote Code Execution via bundle configuration |
| CVE-2026-100846 | 7.6 HIGH | MONAI before 1.5.2 Remote Code Execution via Pickle Deserialization |
| CVE-2026-100842 | 7.0 HIGH | MONAI through 1.6.0 _get_fake_spatial_shape eval() Sandbox Bypass via Attribute Chains |
No comments yet