PT-2026-81276 · Nltk · Nltk
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NLTK versions prior to 3.10.3
Description
Allowlisted pickle loaders trust entire module namespaces instead of specific safe callables. This allows attackers to craft malicious pickle payloads that use the pickle REDUCE mechanism to invoke dangerous in-namespace functions, such as
ReppTokenizer. execute and numpy.f2py.crackfortran.myeval, resulting in remote code execution during the loading of model or tokenizer artifacts.Recommendations
Update NLTK to version 3.10.3.
Exploit
Fix
RCE
Protection Mechanism Failure
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nltk