Skip to content
CVE-2026-79657 - Exploits & Severity

CVE-2026-79657 - Exploits & Severity

Feedly • August 25, 2026

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading.

An unauthenticated attacker over the network can execute arbitrary code by crafting malicious pickle payloads that are loaded when NLTK model or tokenizer artifacts are imported or deserialized.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Available - patch details can be found at

Upgrade NLTK to version 3.10.3 or later. Restrict network access to systems that load untrusted NLTK model or tokenizer artifacts. Implement validation and integrity checking for pickle files before deserialization.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Feedly found the first article mentioning CVE-2026-79657 . See article

NVD published the first details for CVE-2026-79657

A CVSS base score of 9.8 has been assigned.

GitHub Advisories released a security advisory .

[GHSA-vp9c-2pjm-8925] NLTK versions before 3.10.3 contain a remote code execution vulnerability in all

CVE Daily Brief — 2026-08-26

NLTK Mass Disclosure — 4 CVEs, Peak 9.8 (Allowlisted Pickle RCE)

CVE-2026-79657 exploit

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)

Platforms (2)