Critical RCE Vulnerabilities Disclosed in NLTK Toolkit
ID: 0d157dd0-2d49-551d-a154-b98d8065fbf9
STIX ID: report--0d157dd0-2d49-551d-a154-b98d8065fbf9
Feed Name: ThreatCluster
A mass disclosure reports four CVEs in NLTK versions before 3.10.3, highlighted by CVE-2026-79657 (CVSS 9.8) that permits remote code execution through unsafe pickle deserialization by trusting entire module namespaces; other flaws allow file disclosure and denial-of-service. The issues affect many NLP/ML pipelines and security tools that use NLTK; patches are available in NLTK 3.10.3 and users are urged to upgrade immediately. No active exploitation was observed at the time of the report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
