© 2025-2026 PySpect
First version without a known vulnerability: 3.10.0
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences
Fixed in: 3.10.0
Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
Fixed in: 3.10.0
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
Fixed in: 3.10.0
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
Fixed in: 3.10.0
Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
Fixed in: 3.10.0
NLTK vulnerable to Eval Injection via collocations CLI arguments
Fixed in: 3.9.3
In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These classes accept user-controllable JAR paths and execute them via the `java()` function, which invokes `subprocess.Popen()` without integrity verification. This vulnerability is identical to CVE-2026-0848, which was fixed for StanfordSegmenter by adding SHA256 verification. However, the fix was not applied to these additional classes, leaving them susceptible to arbitrary code execution when loading untrusted JAR files.
Fixed in: 3.9.4
Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read
Fixed in: 3.10.0
NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
Fixed in: 3.9.4
Unauthenticated remote shutdown in nltk.app.wordnet_app
Fixed in: 3.9.4
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk
Fixed in: 3.9.4
Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS
NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()
Fixed in: 3.9.3
NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An attacker can supply or replace the JAR file, enabling the execution of arbitrary Java bytecode at import time. This vulnerability can be exploited through methods such as model poisoning, MITM attacks, or dependency poisoning, leading to remote code execution. The issue arises from the direct execution of the JAR file via subprocess with unvalidated classpath input, allowing malicious classes to execute when loaded by the JVM.
Fixed in: 3.9.3
NLTK has a Path Traversal issue
Fixed in: 3.9.3
NLTK has a Zip Slip Vulnerability
Fixed in: 3.9.3
ntlk unsafe deserialization vulnerability
Fixed in: 3.9
NLTK Vulnerable to REDoS
Fixed in: 3.6.6, 2a50a3edc9d35f57ae42a921c621edc160877f4d
Inefficient Regular Expression Complexity in nltk (word_tokenize, sent_tokenize)
Fixed in: 3.6.6, 1405aad979c6b8080dbbc8e0858f89b2e3690341, 3.6.5
NLTK Vulnerable to REDoS
Fixed in: 3.6.4, 277711ab1dec729e626b27aab6fa35ea5efbd7e6
NLTK Vulnerable To Path Traversal
Fixed in: 3.4.5, f59d7ed8df2e0e957f7f247fe218032abdbe9a10