Tag
NLTK versions prior to 3.9.3 fail to verify package integrity after download, allowing remote attackers to perform MitM or DNS poisoning attacks to inject and execute arbitrary code.