Skip to content
NLTKGHSA-5gh2-94qg-qppq

NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

High8.8CVE-2026-71513 · Published Aug 22, 2026 · updated Sep 10, 2026

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the model through allowlisted_pickle_load.

GitHub advisory

Affected versions

PackageAffectedFixed in
nltk
PyPI
>= 3.10.0, < 3.10.33.10.3
Details and references

More NLTK advisories

All NLTK

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.