CVE-2026-78680Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary in the search path or current working directory. Attackers can exploit bare-name binary resolution on Windows via the current working directory or on Unix-like systems via relative PATH entries to execute their binary instead of the legitimate Graphviz tool.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-25); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-25: 1Mentions · 2026-09-02: 1Technical Details · 2026-08-25: 1Technical Details · 2026-09-02: 108-2509-02
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 NLTK (Natural Language Toolkit), Untrusted Search Path / Arbitrary Code Execution, #CVE-2026-78680 (High) -DC-Sep2026-2074 https://dailycve.com/nltk-natural-language-toolkit-untrusted-search-path-arbitrary-code-execution-cve-2026-78680-high-dc-sep2026-2074/

    Post summary

    This entry announces the disclosure of CVE‑2026‑78680 affecting NLTK, highlighting an untrusted search path that could allow arbitrary code execution. No PoC, exploit, patch, or active exploitation details are provided in the snippet.

    0000029
    233 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-78680 Arbitrary Code Execution in NLTK Versions Before 3.10.3 v... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78680 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE-2026-78680, noting an arbitrary code execution flaw in NLTK versions earlier than 3.10.3, and directs readers to a vulnerability details page.

    00000118
    4.1K followersView on X

Explore more