CVE-2025-71408High· 7.0▾ TwilightA flaw was found in NLTK (Natural Language Toolkit). This eval injection vulnerability in the `nltk.collocations` module allows a local attacker to execute arbitrary Python code. By manipulating command-line arguments when `collocations.py…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
0.2% → 0.2%
— → 7
none → high
7 → —
high → none
— → 7
none → high
Last analysed / modified upstream
A flaw was found in NLTK (Natural Language Toolkit). This eval injection vulnerability in the nltk.collocations module allows a local attacker to execute arbitrary Python code. By manipulating command-line arguments when collocations.py is invoked directly, an attacker can bypass validation and execute operating system commands. This can lead to significant impact on the system's confidentiality, integrity, and availability.
nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module — rated Important by Red Hat. Released 2025-01-01, updated 2026-09-15.
Affected:
No fix planned:
Not affected:
Will not fix
Workarounds / mitigations:
nltk.collocations module's internal script (collocations.py) with untrusted command-line arguments. In standard Red Hat deployments, NLTK is typically used as an imported library, which does not expose this vulnerability. If direct invocation is necessary, ensure that all command-line arguments are from trusted sources and are properly validated.Affected packages:
nltk < 3.9.3Patched in:
nltk 3.9.3Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-78676Critical· 9.8gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection (CVE-2026-78676)
CVE-2026-6357Medium· 5.8pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation (CVE-2026-6357)
CVE-2026-78679Medium· 6.5GitPython: GitPython: Arbitrary file read via TagReference.create() (CVE-2026-78679)
CVE-2026-78678Medium· 6.5gitpython: GitPython: Arbitrary file read via Repo.blame() (CVE-2026-78678)
CVE-2026-78675Medium· 5.5GitPython: GitPython: Local file content disclosure via malicious .gitmodules (CVE-2026-78675)
CVE-2026-81725Medium· 5.9nltk: NLTK: Regular Expression Denial of Service via malformed TEI blocks (CVE-2026-81725)