Known Vulnerabilities for MONAI by Project-MONAI
Listed below are 7 of the newest known vulnerabilities associated with "MONAI" by "Project-MONAI".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-100846 json | MONAI before 1.5.2 contains a deserialization of untrusted data vulnerability in the algo_from_pickle function in monai/auto3... | Not Provided | 2026-09-27 | 2026-09-27 |
| CVE-2026-100845 json | MONAI before 1.6.0 contains an unsafe deserialization vulnerability in the NumpyReader class that unconditionally uses numpy.... | Not Provided | 2026-09-27 | 2026-09-27 |
| CVE-2026-100844 json | MONAI before 1.6.0 is vulnerable to OS command injection in the nnUNetV2Runner component (monai.apps.nnunet.nnunetv2_runner).... | Not Provided | 2026-09-27 | 2026-09-27 |
| CVE-2026-100843 json | MONAI versions before 1.6.0 contain a remote code execution vulnerability in the algo_from_pickle() function due to unsafe pi... | Not Provided | 2026-09-27 | 2026-09-27 |
| CVE-2026-100842 json | MONAI through 1.6.0 contains an eval injection vulnerability in _get_fake_spatial_shape() in monai/bundle/scripts.py. The fun... | Not Provided | 2026-09-27 | 2026-09-27 |
| CVE-2026-100841 json | In MONAI 1.6.0, PersistentDataset (monai/data/dataset.py) explicitly rejects the combination track_meta=True with weights_onl... | Not Provided | 2026-09-27 | 2026-09-27 |
| CVE-2026-100840 json | MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _target_ ... | Not Provided | 2026-09-27 | 2026-09-27 |