Disclosure summary
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.
Source-reported weakness categories
CWE-95
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2025-71408
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| nltk | nltk | * {"versionEndExcluding":"3.9.3"} |
Original records & references
- NIST NVD record
- CVE Program record
- aydinnyunus.github.io — Exploit, Press/Media Coverage, Third Party Advisory
- github.com — Patch
- github.com — Issue Tracking, Patch
- github.com — Release Notes
- www.vulncheck.com — Patch, Third Party Advisory
PUBLISHED 2026-07-24T18:16:50-04:00
MODIFIED 2026-10-08T12:16:53-04:00
INGESTED 2026-10-10T20:50:36-04:00