Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-79657

Опубликовано: 25 авг. 2026
Источник: debian
EPSS Низкий

Описание

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nltkfixed3.10.3-1package
nltkno-dsatrixiepackage
nltkpostponedbookwormpackage

Примечания

  • https://github.com/nltk/nltk/security/advisories/GHSA-x99w-6fgc-pmfw

EPSS

Процентиль: 67%
0.01214
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
27 дней назад

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading.

CVSS3: 9.8
nvd
27 дней назад

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading.

github
13 дней назад

NLTK: Allowlisted pickle loaders still permit code execution in current source

CVSS3: 9.8
fstec
около 1 месяца назад

Уязвимость функции punkt_pickle_load() пакета библиотек для символьной и статистической обработки естественного языка NLTK, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 67%
0.01214
Низкий