Critical NLTK Vulnerability: Uncontrolled Search Path in Graphviz 'dot' Binary Execution
A critical vulnerability (CVE-2026-78680, CVSS 8.5) in the Natural Language Toolkit (NLTK) library allows attackers to execute arbitrary code by manipulating the search path for the Graphviz 'dot' binary. This affects NLTK versions <= 3.10.2. Immediate patching to version 3.10.3 or later is recommended to prevent potential code execution.