CVE-2026-78683
Description
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through WarningUnpickler, which does not override find_class() and therefore permits arbitrary class resolution. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code with the privileges of the user running the application. NLTK provides a RestrictedUnpickler for safe deserialization, but it is not used by production code paths. Fixed in 3.10.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nltkPyPI | < 3.10.0 | 3.10.0 |
Affected products
2Patches
Vulnerability mechanics
References
8- github.com/nltk/nltk/security/advisories/GHSA-rhp5-r9x4-f5g2nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-rhp5-r9x4-f5g2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-78683ghsaADVISORY
- www.vulncheck.com/advisories/nltk-before-remote-code-execution-via-unsafe-pickle-deserializationnvdThird Party AdvisoryWEB
- github.com/nltk/nltk/commit/f26b3753038d937b68145daf15e9636f8451053cghsaWEB
- github.com/nltk/nltk/pull/3631ghsaWEB
- github.com/nltk/nltk/releases/tag/v3.10.0ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3734.yamlghsaWEB
News mentions
2- Nltk Library: 16 Vulnerabilities Including Critical RCE Disclosed in BatchVypr Intelligence · Aug 27, 2026
- Nltk Library: Critical RCE and High-Severity Flaws Disclosed TogetherVypr Intelligence · Aug 25, 2026