Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-0848

Опубликовано: 05 мар. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 10

Описание

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An attacker can supply or replace the JAR file, enabling the execution of arbitrary Java bytecode at import time. This vulnerability can be exploited through methods such as model poisoning, MITM attacks, or dependency poisoning, leading to remote code execution. The issue arises from the direct execution of the JAR file via subprocess with unvalidated classpath input, allowing malicious classes to execute when loaded by the JVM.

РелизСтатусПримечание
devel

needed

esm-apps-legacy/xenial

not-affected

vulnerable code not present
esm-apps/bionic

released

3.2.5-1ubuntu0.1+esm4
esm-apps/focal

released

3.4.5-2ubuntu0.1~esm4
esm-apps/jammy

released

3.7-1ubuntu0.1~esm2
esm-apps/noble

released

3.8.1-1ubuntu0.1~esm2
esm-apps/resolute

released

3.9.2-1ubuntu0.1~esm2
esm-apps/xenial

ignored

end of ESM support, was needed
esm-infra-legacy/trusty

not-affected

vulnerable code not present
jammy

needed

Показывать по

EPSS

Процентиль: 53%
0.00809
Низкий

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
redhat
5 месяцев назад

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An attacker can supply or replace the JAR file, enabling the execution of arbitrary Java bytecode at import time. This vulnerability can be exploited through methods such as model poisoning, MITM attacks, or dependency poisoning, leading to remote code execution. The issue arises from the direct execution of the JAR file via subprocess with unvalidated classpath input, allowing malicious classes to execute when loaded by the JVM.

CVSS3: 10
nvd
5 месяцев назад

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An attacker can supply or replace the JAR file, enabling the execution of arbitrary Java bytecode at import time. This vulnerability can be exploited through methods such as model poisoning, MITM attacks, or dependency poisoning, leading to remote code execution. The issue arises from the direct execution of the JAR file via subprocess with unvalidated classpath input, allowing malicious classes to execute when loaded by the JVM.

CVSS3: 10
debian
5 месяцев назад

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due t ...

CVSS3: 10
github
5 месяцев назад

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verification or sandboxing. An attacker can supply or replace the JAR file, enabling the execution of arbitrary Java bytecode at import time. This vulnerability can be exploited through methods such as model poisoning, MITM attacks, or dependency poisoning, leading to remote code execution. The issue arises from the direct execution of the JAR file via subprocess with unvalidated classpath input, allowing malicious classes to execute when loaded by the JVM.

CVSS3: 10
fstec
8 месяцев назад

Уязвимость модуля StanfordSegmenter пакета библиотек для символьной и статистической обработки естественного языка NLTK, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 53%
0.00809
Низкий

10 Critical

CVSS3

Уязвимость CVE-2026-0848