PT-2026-81155 · Pypi+1 · Nltk+1
CVE-2026-78680
·
Published
2026-08-25
·
Updated
2026-09-10
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
NLTK versions prior to 3.10.3
Description
Failure to use validated absolute paths when invoking the Graphviz dot binary in
dependencygraph.dot2img and AlignedSent. repr svg allows for arbitrary code execution. Attackers can exploit bare-name binary resolution by placing a malicious dot binary in the current working directory on Windows or via relative PATH entries on Unix-like systems to execute their own binary instead of the legitimate Graphviz tool.Recommendations
Update NLTK to version 3.10.3 or later.
Exploit
Fix
Uncontrolled Search Path Element
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Graphviz
Nltk