Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. nltk
  4. ›
  5. CVE-2026-71513

CVE-2026-71513: NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

August 22, 2026 (updated September 2, 2026)

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the model through allowlisted_pickle_load.

References

  • github.com/advisories/GHSA-5gh2-94qg-qppq
  • github.com/nltk/nltk/blob/v3.10.2/nltk/picklesec.py
  • github.com/nltk/nltk/commit/c3e37113742a1ebeeb4f2ca58941f320f98805ea
  • nvd.nist.gov/vuln/detail/CVE-2026-71513
  • www.vulncheck.com/advisories/nltk-through-remote-code-execution-via-allowlistunpickler-dotted-name-bypass

Code Behaviors & Features

Detect and mitigate CVE-2026-71513 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.10.0 before 3.10.3

Fixed versions

  • 3.10.3

Solution

Upgrade to version 3.10.3 or above.

Impact 8.8 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-502: Deserialization of Untrusted Data

Source file

pypi/nltk/CVE-2026-71513.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 06 Sep 2026 12:16:39 +0000.