CVE-2026-71513Disclosure(nltk / nltk)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nltk nltk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the model through allowlisted_pickle_load.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nltk

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
nltk

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-22: 1Mentions · 2026-08-23: 1Patch / Workaround · 2026-08-22: 1Patch / Workaround · 2026-08-23: 1Technical Details · 2026-08-22: 1Technical Details · 2026-08-23: 108-2208-23
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-221
Disclosure1
2026-08-231
Patch1
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-71513 - Critical RCE in NLTK AllowlistUnpickler. Attribute traversal bypasses allowlist to execute arbitrary code via crafted transition-parser models. CVSS 8.8. Update to NLTK 3.10.3 immediately. #CVE #NLTK #infosec https://www.valtersit.com/cve/CVE-2026-71513/ #CVE #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #iceland #israel

    Post summary

    The post alerts about a critical RCE in NLTK, describes the vulnerability mechanics, and urges users to update to version 3.10.3 to mitigate the risk.

    0001044
    1.0K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - NLTK TransitionParser Model RCE via AllowlistUnpickler Bypass (CVE-2026-71513) NLTK’s AllowlistUnpickler only validates the pickle module string, not the global name, allowing dotted-name attribute traversal outside the allowlisted namespace. A crafted TransitionParser model loaded via TransitionParser.parse (allowlisted_pickle_load) can trigger arbitrary code execution on load. 👉Affected: nltk < 3.10.3 | Upgrade to 3.10.3

    Post summary

    The post announces CVE-2026-71513, a high‑severity RCE in NLTK caused by AllowlistUnpickler’s weak validation, and urges users to upgrade to version 3.10.3.

    0000088
    291 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnltknltk---

Explore more