Project-monaiのMONAIにおけるEval インジェクションに関する脆弱性
公開日: 2026-10-02T14:56:34+09:00
詳細: https://jvndb.jvn.jp/ja/contents/2026/JVNDB-2026-036184.html
Project-monaiのMONAIにおけるEval インジェクションに関する脆弱性
公開日: 2026-10-02T14:56:34+09:00
詳細: https://jvndb.jvn.jp/ja/contents/2026/JVNDB-2026-036184.html
www.freecodecamp.org/news/build-a...
www.freecodecamp.org/news/build-a...
MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.a...
https://www.thehackerwire.com/vulnerability/CVE-2026-100844/
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.a...
https://www.thehackerwire.com/vulnerability/CVE-2026-100844/
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle...
https://www.thehackerwire.com/vulnerability/CVE-2026-100843/
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle...
https://www.thehackerwire.com/vulnerability/CVE-2026-100843/
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
• PersistentDataset forces unsafe torch.load on cached MetaTensors
• Local user who can write to a shared cache can run code
https://thecircuitry.to/article/monai-160-hit-by-high-severity-rce-flaw-via-pickle-cache-muk13d8j
• PersistentDataset forces unsafe torch.load on cached MetaTensors
• Local user who can write to a shared cache can run code
https://thecircuitry.to/article/monai-160-hit-by-high-severity-rce-flaw-via-pickle-cache-muk13d8j
📊 8.5/10
🏢 Project-MONAI
📝 MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary imp...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87848
#cybersecurity #infosec #cve #euvd
📊 8.5/10
🏢 Project-MONAI
📝 MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ values to arbitrary imp...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-87848
#cybersecurity #infosec #cve #euvd