๐Ÿ” CVE Alert

CVE-2025-71408

HIGH 7.8

NLTK < 3.9.2 Eval Injection via collocations.py Command-Line Arguments

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.

CWE CWE-95
Vendor ntlk
Product ntlk
Published Jul 24, 2026
Last Updated Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for ntlk ntlk

Be the first to know when new high vulnerabilities affecting ntlk ntlk are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

ntlk / ntlk
0 < 3.9.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
aydinnyunus.github.io: https://aydinnyunus.github.io/2026/06/07/command-injection-nltk-collocations-eval/ github.com: https://github.com/nltk/nltk/releases/tag/3.9.3 github.com: https://github.com/nltk/nltk/pull/3465 github.com: https://github.com/nltk/nltk/commit/66f14096d952ec8f04934f515e027534bd4eb0ac vulncheck.com: https://www.vulncheck.com/advisories/nltk-eval-injection-via-collocations-py-command-line-arguments

Credits

Yunus AYDIN