Skip to content
NLTKPYSEC-2026-99

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An attacker can supply or replace the JAR file, enabling the execution of arbit

Critical10.0CVE-2026-0848 · Published Mar 5, 2026 · updated May 20, 2026

Source advisory

Affected versions

PackageAffectedFixed in
nltk
PyPI
< 3.9.33.9.3
Details and references

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An attacker can supply or replace the JAR file, enabling the execution of arbitrary Java bytecode at import time. This vulnerability can be exploited through methods such as model poisoning, MITM attacks, or dependency poisoning, leading to remote code execution. The issue arises from the direct execution of the JAR file via subprocess with unvalidated classpath input, allowing malicious classes to execute when loaded by the JVM.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity from
the CVSS score
Also known as
CVE-2026-0848

More NLTK advisories

All NLTK
DateAdvisory
Mar 4NLTK has a Path Traversal issue
CVE-2026-0847High8.6no fix yet
Mar 9NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()
CVE-2026-0846High8.6fixed in 3.9.3
Mar 18Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS
CVE-2026-66393Mediumfixed in 3.9.4
Mar 18Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk
CVE-2026-33230Medium6.1fixed in 3.9.4
Feb 18NLTK has a Zip Slip Vulnerability
CVE-2025-14009Critical10.0fixed in 3.9.3
Mar 19Unauthenticated remote shutdown in nltk.app.wordnet_app
CVE-2026-33231High7.5fixed in 3.9.4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.