CVE-2026-21851 | Project-MONAI up to 1.5.1 _download_from_ngc_private path traversal (GHSA-9rg3-9pvr-6p27 / EUVD-2026-1039)
A vulnerability was found in Project-MONAI MONAI up to 1.5.1. It has been declared as critical. Affected by this vulnerability is the function _download_from_ngc_private. Such manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-21851. It is possible to launch the attack remotely. No exploit is available.
A patch should be applied to remediate this issue.