NLTK 3.10.3 之前的版本未能验证通过 java() 函数的 per-call options 参数传入的 JVM 选项,攻击者可以借此注入危险的 JVM 标志。攻击者能够向 Stanford 包装类提供恶意选项,例如 -agentpath、-javaagent 或 @argfile,从而实现任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-79657 | 9.8 CRITICAL | NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization |
| CVE-2026-78683 | 9.6 CRITICAL | NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization |
| CVE-2026-79674 | 8.2 HIGH | NLTK 3.10.2 Path Traversal via corpus-reader constructors |
| CVE-2026-78680 | 7.8 HIGH | NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary |
| CVE-2026-78681 | 7.5 HIGH | NLTK before 3.10.3 Entity Expansion DoS via ElementTree |
| CVE-2026-78682 | 7.5 HIGH | NLTK before 3.10.3 SSRF Protection Bypass via Proxy |
| CVE-2026-79676 | 5.9 MEDIUM | NLTK before 3.10.3 Path Traversal via Symlink Bypass |
No comments yet