CyberRota Analysis
AI-GeneratedThe NLTK (Natural Language Toolkit) prior to version 3.9.3 is vulnerable to an eval injection in the nltk.collocations module, allowing attackers to execute arbitrary Python code through manipulated command-line arguments. This vulnerability can lead to unauthorized code execution, including OS commands, posing a significant risk to systems using this library. Organizations utilizing NLTK for natural language processing should prioritize patching to version 3.9.3 or later to mitigate this high-severity threat.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.
Related CVEs
Other vulnerabilities affecting the same vendor(s)