CVE-2024-39705

CRITICAL

NLTK < 3.9 - Remote Code Execution via Pickle Deserialization

Title source: llm
STIX 2.1

Description

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

Scores

CVSS v3 9.8
EPSS 0.1079
EPSS Percentile 93.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
pypi/nltk 0 - 3.9PyPI
Published Jun 27, 2024
Tracked Since Feb 18, 2026