Junglewise Threat Intelligence

CVE-2026-12252: NLTK arbitrary code execution in Stanford interface classes

CVE-2026-12252 · Severity: high · CVSS 7.8 · Published 2026-07-04

Technologies: Nltk. Vendors: PyPI.

Executive brief

The NLTK library, a popular tool for processing human language data, contains a security flaw in its interface for Stanford NLP tools. If a user is tricked into loading a malicious file, an attacker could execute unauthorized code on the user's system. This could lead to a full system compromise, data theft, or the installation of malware.

Technical details

A code injection vulnerability exists in NLTK's Stanford interface classes, including StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser. These classes accept user-controllable JAR paths and execute them using the `java()` function, which internally calls `subprocess.Popen()` without verifying the JAR's integrity or origin. While a similar issue was previously patched in the StanfordSegmenter class using SHA256 verification, these specific classes remained unpatched. An attacker can achieve arbitrary code execution if they can convince a user to point the library at a malicious JAR file.

Affected products

  • nltk nltk <= 3.9.3

Timeline

  • 2026-07-04: advisory: NVD publication date

References

Related threats