Product
critical
advisory
Remote Code Execution in NLTK via Unsafe Pickle Deserialization
6 TTPs 1 CVEThe NLTK library versions up to 3.9.4 are vulnerable to arbitrary code execution when processing crafted model files due to unsafe pickle deserialization in the TransitionParser.parse() method.
NLTK +2
denial-of-service
xml-vulnerability
cve-2026-78681
deserialization
rce
python
6t
1c
updated
high
advisory
Remote Code Execution in NLTK AllowlistUnpickler
1 rule 4 TTPs 1 CVENLTK versions prior to 3.10.3 are vulnerable to remote code execution due to improper validation of dotted names during the unpickling of transition-parser models.
nltk +2
1r
4t
1c
updated
high
advisory
Arbitrary File Read in NLTK via Path Traversal
2 TTPs 1 CVENLTK versions prior to 3.10.0 are vulnerable to path traversal (CVE-2026-12243) due to improper sequence decoding in nltk.data.load(), allowing attackers to read arbitrary files.
nltk
2t
1c