PT-2026-81155 · Pypi+1 · Nltk+1

CVE-2026-78680

·

Published

2026-08-25

·

Updated

2026-09-10

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NLTK versions prior to 3.10.3
Description Failure to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent. repr svg allows for arbitrary code execution. Attackers can exploit bare-name binary resolution by placing a malicious dot binary in the current working directory on Windows or via relative PATH entries on Unix-like systems to execute their own binary instead of the legitimate Graphviz tool.
Recommendations Update NLTK to version 3.10.3 or later.

Exploit

Fix

Uncontrolled Search Path Element

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78680
GHSA-54XP-3WW7-6WJG
GHSA-6HWM-XVPH-95VM
PYSEC-2026-3868

Affected Products

Graphviz
Nltk