nltk Vulnerable to Cross-site Scripting
Description
NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, nltk.app.wordnet_app contains a reflected cross-site scripting issue in the lookup_... route. A crafted lookup_ URL can inject arbitrary HTML/JavaScript into the response page because attacker-controlled word data is reflected into HTML without escaping. This impacts users running the local WordNet Browser server and can lead to script execution in the browser origin of that application. Commit 1c3f799607eeb088cab2491dcf806ae83c29ad8f fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nltkPyPI | < 3.9.4 | 3.9.4 |
Affected products
20- osv-coords19 versionspkg:apk/chainguard/apache-beam-python-3.11-sdkpkg:apk/chainguard/apache-beam-python-3.12-sdkpkg:apk/chainguard/apache-beam-python-3.13-sdkpkg:apk/chainguard/kubeflow-pipelines-visualization-serverpkg:apk/chainguard/label-studiopkg:apk/chainguard/nemopkg:apk/chainguard/open-webuipkg:apk/chainguard/py3.11-nltkpkg:apk/chainguard/py3.12-nltkpkg:apk/chainguard/py3.13-nltkpkg:apk/chainguard/py3-nltkpkg:apk/wolfi/kubeflow-pipelines-visualization-serverpkg:apk/wolfi/open-webuipkg:apk/wolfi/py3.11-nltkpkg:apk/wolfi/py3.12-nltkpkg:apk/wolfi/py3.13-nltkpkg:apk/wolfi/py3-nltkpkg:pypi/nltkpkg:rpm/opensuse/python-nltk&distro=openSUSE%20Tumbleweed
< 2.71.0-r8+ 18 more
- (no CPE)range: < 2.71.0-r8
- (no CPE)range: < 2.71.0-r2
- (no CPE)range: < 2.71.0-r2
- (no CPE)range: < 2.16.0-r3
- (no CPE)range: < 1.23.0-r1
- (no CPE)range: < 2.7.2-r1
- (no CPE)range: < 0.8.12-r2
- (no CPE)range: < 3.9.4-r0
- (no CPE)range: < 3.9.4-r0
- (no CPE)range: < 3.9.4-r0
- (no CPE)range: < 3.9.4-r0
- (no CPE)range: < 2.16.0-r3
- (no CPE)range: < 0.8.12-r2
- (no CPE)range: < 3.9.4-r0
- (no CPE)range: < 3.9.4-r0
- (no CPE)range: < 3.9.4-r0
- (no CPE)range: < 3.9.4-r0
- (no CPE)range: < 3.9.4
- (no CPE)range: < 3.9.4-1.1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-gfwx-w7gr-fvh7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-33230ghsaADVISORY
- github.com/nltk/nltk/commit/1c3f799607eeb088cab2491dcf806ae83c29ad8fghsax_refsource_MISCWEB
- github.com/nltk/nltk/commit/40d0bc1d484a3458d6a63ecb5ba4957ab16ba14eghsax_refsource_MISCWEB
- github.com/nltk/nltk/security/advisories/GHSA-gfwx-w7gr-fvh7ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.