NVD HIGH: CVE-2026-100844 — MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner c...
MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner). User-controlled values taken from the YAML configuration file (notably dataset_name_or_id) and from CLI/kwargs arguments are concatenated into a command string without quoting or validation and then passed to subprocess with shell=True, so shell metacharacters (e.g., ';' on
CVE-2026-100844