The NLTK library versions up to 3.9.4 are vulnerable to arbitrary code execution when processing crafted model files due to unsafe pickle deserialization in the TransitionParser.parse() method.
NLTK +2
denial-of-service
xml-vulnerability
cve-2026-78681
deserialization
rce
python
6t
1c
updated