CVE-2025-71408
HIGHNLTK < 3.9.2 Eval Injection via collocations.py Command-Line Arguments
Title source: cnaDescription
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.
References (5)
Core 5
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://aydinnyunus.github.io/2026/06/07/command-injection-nltk-collocations-eval/
Patch patch
Patch Commit
https://github.com/nltk/nltk/commit/66f14096d952ec8f04934f515e027534bd4eb0ac
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/nltk-eval-injection-via-collocations-py-command-line-arguments
Scores
CVSS v3
7.8
EPSS
0.0016
EPSS Percentile
5.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-95
Status
published
Products (1)
ntlk/ntlk
< 3.9.3
Published
Jul 24, 2026
Tracked Since
Jul 25, 2026