threataft.com
Critical RCE Vulnerabilities Disclosed in NLTK Toolkit
Article Content
A mass disclosure of four CVEs affecting NLTK versions before 3.10.3 was announced, with CVE-2026-79657 rated at CVSS 9.8. This critical vulnerability allows remote code execution through unsafe pickle deserialization, where allowlisted loaders trust entire module namespaces. Attackers can exploit this by crafting malicious pickle payloads that invoke dangerous functions during model loading. Other vulnerabilities include CVE-2026-78683 (9.6), CVE-2026-78681 (8.7), and CVE-2026-78682 (7.5), impacting file disclosure and denial of service. No active exploitation has been reported at the time of publication, but users are urged to update to NLTK 3.10.3 immediately. The vulnerabilities affect a wide range of NLP/ML pipelines and security tools that utilize NLTK. Patches for all vulnerabilities are available in the fixed version.
Key Points: • CVE-2026-79657 allows RCE via unsafe pickle deserialization in NLTK. • Four CVEs disclosed, with CVSS scores ranging from 7.5 to 9.8. • Immediate upgrade to NLTK 3.10.3 is recommended to mitigate risks.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.