{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nltk--3.10.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.6,"id":"CVE-2026-78683"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NLTK (3.9.4)","nltk","NLTK (\u003c 3.10.3)"],"_cs_severities":["critical"],"_cs_tags":["denial-of-service","xml-vulnerability","cve-2026-78681","deserialization","rce","nltk","python"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eNLTK (Natural Language Toolkit) versions prior to 3.10.0 contain a critical vulnerability in the TransitionParser.parse() method, located within the nltk/parse/transitionparser.py file. This vulnerability arises because the library uses an insecure default setting for the pickle_load() function, specifically setting restricted=False. By default, this utilizes the standard WarningUnpickler which fails to restrict class resolution during the deserialization process.\u003c/p\u003e\n\u003cp\u003eWhen an application utilizing NLTK processes an attacker-controlled or malicious model file, the deserialization of that object allows for the execution of arbitrary Python code. This occurs because the library does not utilize the provided RestrictedUnpickler for production tasks, thereby allowing gadget chains to execute within the context of the running application. This vulnerability is patched in version 3.10.0 and carries a CVSS 3.1 base score of 9.6.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to execute arbitrary code with the full privileges of the user running the application. This could lead to full system compromise, data exfiltration, or the deployment of persistent threats depending on the service's environment. Applications that process untrusted NLTK model files are at the highest risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the NLTK library to version 3.10.0 or later across all production and development environments.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation or signing for all model files processed by applications to ensure they originate from a trusted source.\u003c/li\u003e\n\u003cli\u003eAudit applications using the TransitionParser module to ensure that user-supplied input is not directly passed to the parsing engine.\u003c/li\u003e\n\u003cli\u003eRestrict application service account permissions to the principle of least privilege to minimize the impact of a potential RCE event.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-25T18:10:07Z","date_published":"2026-08-25T04:05:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nltk-pickle-rce/","summary":"The NLTK library versions up to 3.9.4 are vulnerable to arbitrary code execution when processing crafted model files due to unsafe pickle deserialization in the TransitionParser.parse() method.","title":"Remote Code Execution in NLTK via Unsafe Pickle Deserialization","url":"https://feed.craftedsignal.io/briefs/2026-08-nltk-pickle-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - NLTK (\u003c 3.10.3)","version":"https://jsonfeed.org/version/1.1"}