
🚨High - NLTK Untrusted JAR Code Execution in Stanford Interfaces (CVE-2026-12252) Five of NLTK's Stanford wrapper classes - StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser - accept user-controllable JAR paths and execute them via java() / subprocess.Popen() with no integrity verification. Loading an attacker-supplied or tampered JAR through any of these classes yields arbitrary code execution. It's the same flaw as CVE-2026-0848 (fixed for StanfordSegmenter with SHA256 verification), but that fix was never applied to these five classes. 👉Affected: nltk <= 3.9.3 - avoid loading untrusted JAR paths via the Stanford interfaces; apply the patched release once available.
Post summary
The tweet details a code execution vulnerability in Stanford interface wrappers and urges users to avoid untrusted JARs and apply the forthcoming patch.
