CVE-2025-71408

Published: Lug 25, 2026 Last Modified: Lug 25, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 8,5
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 7,8
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.

95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Access Control Integrity Availability Other Non-Repudiation
Potential Impacts:
Read Files Or Directories Read Application Data Bypass Protection Mechanism Gain Privileges Or Assume Identity Execute Unauthorized Code Or Commands Hide Activities
Applicable Platforms
Languages: Java, JavaScript, Python, Perl, PHP, Ruby, Interpreted
Technologies: AI/ML
View CWE Details
https://aydinnyunus.github.io/2026/06/07/command-injection-nltk-collocations-ev…
https://github.com/nltk/nltk/commit/66f14096d952ec8f04934f515e027534bd4eb0ac
https://github.com/nltk/nltk/pull/3465
https://github.com/nltk/nltk/releases/tag/3.9.3
https://www.vulncheck.com/advisories/nltk-eval-injection-via-collocations-py-co…