CVE-2025-71408 NLTK Eval Injection Vulnerability
An eval injection vulnerability exists in the nltk.collocations module of NLTK (Natural Language Toolkit) versions prior to 3.9.3, allowing an attacker to exploit this by controlling command-line arguments passed to collocations.py, which are then unsafely passed to eval() enabling remote code execution on the affected system.
A critical eval injection vulnerability, identified as CVE-2025-71408, has been discovered in the Natural Language Toolkit (NLTK) Python library, affecting all versions prior to 3.9.3. This flaw resides within the nltk.collocations module, specifically when the collocations.py script is directly invoked via the command line. The vulnerability arises because the script's __main__ block passes user-supplied command-line arguments directly to Python's eval() function without adequate sanitization or allowlist validation. An attacker who can control these command-line arguments can inject arbitrary Python expressions, bypassing the intended attribute lookup mechanism. This allows for the execution of arbitrary Python code, including operating system commands through Python's os module, leading to remote code execution (RCE) on the compromised system. The vulnerability presents a significant risk to applications and environments utilizing affected NLTK versions, especially those that process untrusted input via collocations.py.
Attack Chain
- An attacker crafts a malicious Python expression designed to execute arbitrary code or OS commands.
- The attacker delivers or injects this malicious expression into the command-line arguments intended for the
collocations.pyscript. - A vulnerable system or application executes
collocations.py, passing the attacker-controlled command-line arguments. - The
__main__block withincollocations.pydirectly processes these arguments and feeds them into theeval()function. - Due to the
eval injectionvulnerability, the malicious Python expression is evaluated instead of benign data. - Arbitrary Python code, including system-level commands leveraging the
osmodule (e.g.,os.system("malicious_command")), is executed on the host. - The attacker achieves remote code execution on the system, potentially leading to full system compromise, data exfiltration, or further lateral movement.
Impact
Successful exploitation of CVE-2025-71408 grants attackers arbitrary code execution capabilities on the host system where vulnerable NLTK versions are deployed. This can lead to complete system compromise, allowing attackers to install malware, establish persistence, exfiltrate sensitive data, or disrupt operations. The broad use of NLTK in data science, academic research, and various applications suggests a wide potential impact across multiple sectors if not patched. The CVSS v3.1 Base Score of 7.8 indicates a high severity risk.
Recommendation
- Prioritize patching all instances of NLTK (Natural Language Toolkit) to version 3.9.3 or later to remediate CVE-2025-71408 immediately.
- Implement robust input validation and sanitization for any application that passes untrusted user input to command-line arguments, especially when those arguments are processed by Python scripts that may use functions like
eval(). - Monitor process creation logs for unusual child processes spawned by Python interpreters, particularly if
collocations.pyis known to run on your systems.