Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-71513: NLTK can run malicious code when parsing models

CVE-2026-71513 · published 1 month ago
Summary

Versions of the Natural Language Toolkit (NLTK) up to 3.10.2 allow specially crafted language models to execute any code on the system during parsing. This could let an attacker take control of the server or workstation running the affected NLTK version. Update NLTK to version 3.10.3 or later, or stop using untrusted models, to eliminate the risk.

What to do
  • Update nltk team nltk to version 3.10.3.
  • Update debian nltk to version 3.10.3-1.
  • Update nltk to version 3.10.3.
  • Update nltk nltk to version 3.10.3 or later.
Affected software
Ecosystem VendorProductAffected versions
pip nltk team nltk >= 3.10.0, < 3.10.3
Fix: upgrade to 3.10.3
– nltk nltk < 3.10.3
Debian:11 debian nltk All versions
Debian:12 debian nltk All versions
Debian:13 debian nltk All versions
Debian:14 debian nltk < 3.10.3-1
Fix: upgrade to 3.10.3-1
Ubuntu:Pro:14.04:LTS canonical nltk All versions
Ubuntu:Pro:16.04:LTS canonical nltk All versions
Ubuntu:Pro:18.04:LTS canonical nltk All versions
Ubuntu:Pro:20.04:LTS canonical nltk All versions
Ubuntu:Pro:22.04:LTS canonical nltk All versions
Ubuntu:Pro:24.04:LTS canonical nltk All versions
Ubuntu:Pro:26.04:LTS canonical nltk All versions
PyPI – nltk >= 3.10.0, < 3.10.3
Fix: upgrade to 3.10.3
Original advisory text
NLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name Bypass
NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the model through allowlisted_pickle_load.
Severity
9.9 Critical
CVSS 4.0: 9.9 (OSV)
CVSS 3.1: 8.8 (OSV)
CVSS 3.1: 8.8 (NVD)
CVSS 4.0: 8.7 (NVD)
Exploitation
EPSS 1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published22 Aug 2026
Updated27 Sep 2026
First seen22 Aug 2026
Track software like this
Free during beta