SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2025-71408

HIGH · CVSS 7.8 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

The NLTK (Natural Language Toolkit) prior to version 3.9.3 is vulnerable to an eval injection in the nltk.collocations module, allowing attackers to execute arbitrary Python code through manipulated command-line arguments. This vulnerability can lead to unauthorized code execution, including OS commands, posing a significant risk to systems using this library. Organizations utilizing NLTK for natural language processing should prioritize patching to version 3.9.3 or later to mitigate this high-severity threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-71408
Severity
HIGH
CVSS
7.8
EPSS
0.18%

Original NVD Description

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.

Related CVEs

Other vulnerabilities affecting the same vendor(s)