Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-71408

Опубликовано: 24 июл. 2026
Источник: debian
EPSS Низкий

Описание

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nltkfixed3.9.3-1package

Примечания

  • https://aydinnyunus.github.io/2026/06/07/command-injection-nltk-collocations-eval/

  • https://github.com/nltk/nltk/pull/3465

  • Fixed by: https://github.com/nltk/nltk/commit/e373c8c3d10e236672ef65c38ca7d24612941553 (3.9.3)

EPSS

Процентиль: 5%
0.00158
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
6 дней назад

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.

CVSS3: 7.8
nvd
6 дней назад

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.

CVSS3: 7.8
github
6 дней назад

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.

CVSS3: 7.8
fstec
около 2 месяцев назад

Уязвимость функции eval() компонента nltk.collocations пакета библиотек для символьной и статистической обработки естественного языка NLTK, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 5%
0.00158
Низкий