Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-79675: NLTK library can run malicious code via unsafe Java options
CVE-2026-79675 · published 9 days ago
Summary
Versions of the NLTK Python library before the latest release let attackers add dangerous Java settings when calling its java() function. This can let an attacker run arbitrary code on the system. Update NLTK to the newest version or stop using the java() feature until you can apply the fix.
What to do
- Update debian nltk to version 3.10.3-1.
- Update nltk to version 3.10.3.
- Update nltk nltk to version 3.10.3 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | nltk | nltk | < 3.10.3 |
| Debian:11 | debian | nltk | All versions |
| Debian:12 | debian | nltk | All versions |
| Debian:13 | debian | nltk | All versions |
| Debian:14 | debian | nltk |
< 3.10.3-1 Fix: upgrade to 3.10.3-1
|
| Ubuntu:Pro:24.04:LTS | canonical | nltk | All versions |
| Ubuntu:Pro:14.04:LTS | canonical | nltk | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | nltk | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | nltk | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | nltk | All versions |
| Ubuntu:Pro:22.04:LTS | canonical | nltk | All versions |
| Ubuntu:Pro:26.04:LTS | canonical | nltk | All versions |
| PyPI | – | nltk |
< 3.10.3 Fix: upgrade to 3.10.3
|
Original advisory text
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicio...
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary code execution.
References
- https://github.com/nltk/nltk/security/advisories/GHSA-m4rf-3fr8-xwx3 Third Party Advisory
- https://www.vulncheck.com/advisories/nltk-before-jvm-argument-injection-via-per-... third-party-advisory
- https://security-tracker.debian.org/tracker/CVE-2026-79675 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-79675 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-79675 Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-79675 Vendor Advisory
- https://github.com/nltk/nltk/commit/8fa9650b6009aacfdebbc33d2a08d32c0858ea6c URL
- https://github.com/nltk/nltk Product
- https://github.com/nltk/nltk/releases/tag/v3.10.3 URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79675... Vendor Advisory
Severity
9.9
Critical
CVSS 3.1: 9.8 (MITRE)
CVSS 4.0: 9.9 (OSV)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Timeline
Published25 Aug 2026
Updated2 Sep 2026
First seen25 Aug 2026
Sources
GHSA-m4rf-3fr8-xwx3 · GHSA
DEBIAN-CVE-2026-79675 · OSV
UBUNTU-CVE-2026-79675 · OSV
CVE-2026-79675 · OSV
CVE-2026-79675 · NVD
CVE-2026-79675 · MITRE
GHSA-m4rf-3fr8-xwx3 · OSV
Monitor software like this
Free during beta