Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-79675: NLTK library can run malicious code via unsafe Java options

CVE-2026-79675 · published 9 days ago
Summary

Versions of the NLTK Python library before the latest release let attackers add dangerous Java settings when calling its java() function. This can let an attacker run arbitrary code on the system. Update NLTK to the newest version or stop using the java() feature until you can apply the fix.

What to do
  • Update debian nltk to version 3.10.3-1.
  • Update nltk to version 3.10.3.
  • Update nltk nltk to version 3.10.3 or later.
Affected software
Ecosystem VendorProductAffected versions
nltk nltk < 3.10.3
Debian:11 debian nltk All versions
Debian:12 debian nltk All versions
Debian:13 debian nltk All versions
Debian:14 debian nltk < 3.10.3-1
Fix: upgrade to 3.10.3-1
Ubuntu:Pro:24.04:LTS canonical nltk All versions
Ubuntu:Pro:14.04:LTS canonical nltk All versions
Ubuntu:Pro:16.04:LTS canonical nltk All versions
Ubuntu:Pro:18.04:LTS canonical nltk All versions
Ubuntu:Pro:20.04:LTS canonical nltk All versions
Ubuntu:Pro:22.04:LTS canonical nltk All versions
Ubuntu:Pro:26.04:LTS canonical nltk All versions
PyPI nltk < 3.10.3
Fix: upgrade to 3.10.3
Original advisory text
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicio...
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary code execution.
Severity
9.9 Critical
CVSS 3.1: 9.8 (MITRE)
CVSS 4.0: 9.9 (OSV)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Timeline
Published25 Aug 2026
Updated2 Sep 2026
First seen25 Aug 2026
Monitor software like this
Free during beta