Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33230

Опубликовано: 20 мар. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, nltk.app.wordnet_app contains a reflected cross-site scripting issue in the lookup_... route. A crafted lookup_<payload> URL can inject arbitrary HTML/JavaScript into the response page because attacker-controlled word data is reflected into HTML without escaping. This impacts users running the local WordNet Browser server and can lead to script execution in the browser origin of that application. Commit 1c3f799607eeb088cab2491dcf806ae83c29ad8f fixes the issue.

A flaw was found in NLTK (Natural Language Toolkit), a suite of open source Python modules for Natural Language Processing. The nltk.app.wordnet_app component contains a reflected cross-site scripting (XSS) vulnerability. A remote attacker can exploit this by crafting a malicious URL that injects arbitrary HTML or JavaScript code into the response page. This can lead to script execution in the browser for users running the local WordNet Browser server.

Отчет

MODERATE: This reflected cross-site scripting flaw in NLTK's WordNet Browser application allows for arbitrary script execution. Exploitation requires a user to be running the local WordNet Browser server and then accessing a specially crafted URL. This vulnerability affects Red Hat products that include the NLTK component and utilize the WordNet Browser functionality.

Меры по смягчению последствий

To mitigate this issue, avoid running the NLTK WordNet Browser server (nltk.app.wordnet_app) if it is not required. If the server must be run, users should exercise caution and avoid accessing untrusted or suspicious URLs while the application is active.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-minimal-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-supported-rhel8Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/de-supported-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2449825nltk: NLTK: Script execution via reflected cross-site scripting in WordNet Browser

EPSS

Процентиль: 26%
0.00331
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
5 месяцев назад

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a reflected cross-site scripting issue in the `lookup_...` route. A crafted `lookup_<payload>` URL can inject arbitrary HTML/JavaScript into the response page because attacker-controlled `word` data is reflected into HTML without escaping. This impacts users running the local WordNet Browser server and can lead to script execution in the browser origin of that application. Commit 1c3f799607eeb088cab2491dcf806ae83c29ad8f fixes the issue.

CVSS3: 6.1
nvd
5 месяцев назад

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a reflected cross-site scripting issue in the `lookup_...` route. A crafted `lookup_<payload>` URL can inject arbitrary HTML/JavaScript into the response page because attacker-controlled `word` data is reflected into HTML without escaping. This impacts users running the local WordNet Browser server and can lead to script execution in the browser origin of that application. Commit 1c3f799607eeb088cab2491dcf806ae83c29ad8f fixes the issue.

CVSS3: 6.1
debian
5 месяцев назад

NLTK (Natural Language Toolkit) is a suite of open source Python modul ...

CVSS3: 6.1
github
5 месяцев назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk

EPSS

Процентиль: 26%
0.00331
Низкий

6.1 Medium

CVSS3