{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/monai--1.6.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MONAI (\u003c 1.6.0)"],"_cs_severities":["high"],"_cs_tags":["rce","command-injection","python","monai"],"_cs_type":"advisory","_cs_vendors":["MONAI"],"content_html":"\u003cp\u003eMONAI versions prior to 1.6.0 are susceptible to OS command injection due to insecure handling of user-controlled configuration parameters within YAML files. Specifically, parameters such as 'dataset_name_or_id' or various CLI arguments are concatenated into strings and processed by the \u003ccode\u003esubprocess\u003c/code\u003e module with \u003ccode\u003eshell=True\u003c/code\u003e. Because this input is not properly quoted or validated, an attacker can inject shell metacharacters - such as '\u0026amp;' on Windows or ';' on Linux - to escape the intended command context and execute arbitrary system instructions. This vulnerability (CWE-78) is triggered whenever a victim loads a malicious YAML configuration file into a training or validation pipeline. Defenders should prioritize updating the MONAI package to version 1.6.0 or later to mitigate the risk of remote code execution on systems running medical imaging training tasks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to execute arbitrary commands with the privileges of the user running the MONAI training or validation scripts. This can lead to full system compromise, exfiltration of sensitive medical imaging datasets, or the deployment of persistent malware on workstations and servers used for research and clinical analysis.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the MONAI package to version 1.6.0 or higher across all development and production environments.\u003c/li\u003e\n\u003cli\u003eImplement strict validation and input sanitization for any YAML configuration files used in machine learning pipelines.\u003c/li\u003e\n\u003cli\u003eRun training jobs under restricted service accounts with minimal filesystem and network permissions to limit the impact of potential command execution.\u003c/li\u003e\n\u003cli\u003eMonitor process creation logs for unusual child processes spawned by python.exe or python3, particularly those involving shell command separators.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T20:57:37Z","date_published":"2026-08-18T20:57:29Z","id":"https://feed.craftedsignal.io/briefs/2026-08-monai-command-injection/","summary":"The MONAI library contains a command injection vulnerability where unsanitized configuration values in YAML files are passed to shell execution, allowing arbitrary code execution.","title":"OS Command Injection Vulnerability in MONAI","url":"https://feed.craftedsignal.io/briefs/2026-08-monai-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - MONAI (\u003c 1.6.0)","version":"https://jsonfeed.org/version/1.1"}