VYPR
High severity8.8NVD Advisory· Published Aug 22, 2026· Updated Sep 16, 2026

CVE-2026-71513

CVE-2026-71513

Description

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the model through allowlisted_pickle_load.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
nltkPyPI
>= 3.10.0, < 3.10.33.10.3

Affected products

5

Patches

Vulnerability mechanics

References

5

News mentions

1