Skip to content
NLTKGHSA-9r6g-266r-89x4

NLTK Stanford wrapper classes execute untrusted JAR files without verification

High7.8CVE-2026-12252 · Published Jul 4, 2026 · updated Oct 2, 2026

In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These classes accept user-controllable JAR paths and execute them via the `java()` function, which invokes `subprocess.Popen()` without integrity verification. This vulnerability is identical to CVE-2026-0848, which was fixed for StanfordSegmenter by adding SHA256 verification. However, the fix was not applied to these additional classes, leaving them susceptible to arbitrary code execution when loading untrusted JAR files.

GitHub advisory

Affected versions

PackageAffectedFixed in
nltk
PyPI
< 3.9.43.9.4
Details and references

More NLTK advisories

All NLTK
Advisory
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
High7.5Jul 31
NLTK: arbitrary file read
High7.5Jul 31
NLTK: path traversal
High7.5Jul 31
NLTK vulnerable to Eval Injection via collocations CLI arguments
High7.8Jul 25
NLTK: code execution
High7.8Jul 4
NLTK: path traversal
High7.5Jun 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.