Tag

#NLTK

articleHIGH 8.5

Critical NLTK Vulnerability: Uncontrolled Search Path in Graphviz 'dot' Binary Execution

A critical vulnerability (CVE-2026-78680, CVSS 8.5) in the Natural Language Toolkit (NLTK) library allows attackers to execute arbitrary code by manipulating the search path for the Graphviz 'dot' binary. This affects NLTK versions <= 3.10.2. Immediate patching to version 3.10.3 or later is recommended to prevent potential code execution.

1 source
blogCRITICAL 9.8

Understanding and Defending Against JVM Argument Injection in NLTK

This educational analysis covers CVE-2026-79675, a critical vulnerability in the Natural Language Toolkit (NLTK) that allows attackers to inject malicious JVM flags via the java() function. With a CVSS score of 9.8, this flaw enables arbitrary code execution, posing significant risks to affected systems. We will explore the root cause, attack surface, exploitation mechanics, and provide defensive strategies.

1 source
blogHIGH 7.5

Understanding and Defending Against Arbitrary Local File Read Vulnerability in NLTK

This educational analysis covers CVE-2026-63312, an arbitrary local file read vulnerability in the Natural Language Toolkit (NLTK) before version 3.10.0. The vulnerability allows attackers to bypass security restrictions and read sensitive files. We will delve into the root cause, attack surface, exploitation mechanics, real-world impact, and defensive strategies.

1 source
newsHIGH 7.5

CVE-2026-62388: NLTK Insecure Default Configuration in pathsec.py Allows Path Traversal and Pickle Deserialization Bypass

A vulnerability in NLTK versions before 3.10.0 allows attackers to bypass path traversal and pickle deserialization protections due to insecure default configuration. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Affected users should update NLTK to version 3.10.0 or later.

1 source
articleHIGH 7.5

Critical Symlink-Based Sandbox Bypass in NLTK FramenetCorpusReader (CVE-2026-62384)

CVE-2026-62384 is a critical symlink-based sandbox bypass vulnerability in NLTK's FramenetCorpusReader, affecting versions before 3.10.2. This vulnerability allows attackers to read arbitrary XML files outside the corpus root, with a CVSS score of 7.5. Organizations should immediately upgrade to NLTK version 3.10.2 or later to mitigate this high-severity threat.

1 source