Skip to content
COOEY

EXPOSURES › CVE-2026-78683

CVE-2026-78683

CRITICAL
DETAIL
SourceNVD · cve Published2026-08-25 CVSS9.6 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-78683 ↗

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, routing deserialization through WarningUnpickler, which does not override find_class() and therefore permits arbitrary class resolution. When an application loads an attacker-crafted model file, embedded pickle gadget chains execute arbitrary Python code with the privileges of the user running the application. NLTK provides a RestrictedUnpickler for safe deserialization, but it is not used by production code paths. Fixed in 3.10.0.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.