{"data":{"ecosystem":"pypi","name":"nltk","url":"https://aisecwatch.com/packages/pypi/nltk","latestVersion":"3.10.3","firstReleaseAt":"2009-07-15T09:32:16.349Z","repository":"https://github.com/nltk/nltk","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":["http"],"fromDependencies":["pypi:requests"]},"dependencies":[{"ecosystem":"pypi","name":"click","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"defusedxml","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"joblib","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"matplotlib","versionSpec":null,"scope":"extra:plot"},{"ecosystem":"pypi","name":"numpy","versionSpec":null,"scope":"extra:machine-learning"},{"ecosystem":"pypi","name":"pyparsing","versionSpec":null,"scope":"extra:tgrep"},{"ecosystem":"pypi","name":"python-crfsuite","versionSpec":null,"scope":"extra:machine-learning"},{"ecosystem":"pypi","name":"regex","versionSpec":">=2021.8.3","scope":"runtime"},{"ecosystem":"pypi","name":"requests","versionSpec":null,"scope":"extra:corenlp"},{"ecosystem":"pypi","name":"scikit-learn","versionSpec":null,"scope":"extra:machine-learning"},{"ecosystem":"pypi","name":"scipy","versionSpec":null,"scope":"extra:machine-learning"},{"ecosystem":"pypi","name":"tqdm","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"twython","versionSpec":null,"scope":"extra:twitter"}],"advisories":[{"id":"7dc5638c-9014-4db7-bb05-09280d7a3939","url":"https://aisecwatch.com/issues/7dc5638c-9014-4db7-bb05-09280d7a3939","cveId":"CVE-2026-79675","title":"GHSA-m4rf-3fr8-xwx3: NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)","headline":null,"severity":"critical","publishedAt":"2026-09-01T20:38:22.000Z","affected":["nltk@<= 3.10.2 (fixed: 3.10.3)"],"epssScore":0.00775,"matchedBy":"ecosystem"},{"id":"0a1e27fd-8c5d-41e3-8f92-ffb7f85ed27a","url":"https://aisecwatch.com/issues/0a1e27fd-8c5d-41e3-8f92-ffb7f85ed27a","cveId":"CVE-2026-78683","title":"CVE-2026-78683: NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the…","headline":"NLTK unsafe pickle deserialization in TransitionParser.parse() method","severity":"critical","publishedAt":"2026-08-25T02:16:53.033Z","affected":["nltk@<= 3.9.4 (fixed: 3.10.0)"],"epssScore":0.0051,"matchedBy":"ecosystem"},{"id":"ef4e1fe0-1a85-460e-acc5-85eecd823c9a","url":"https://aisecwatch.com/issues/ef4e1fe0-1a85-460e-acc5-85eecd823c9a","cveId":"CVE-2026-12261","title":"CVE-2026-12261: A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model…","headline":"nltk.downloader cross-package resource and model poisoning via shared namespaces","severity":"high","publishedAt":"2026-08-07T07:16:26.377Z","affected":["nltk@< 3.10.0 (fixed: 3.10.0)"],"epssScore":0.00211,"matchedBy":"ecosystem"},{"id":"dbdc380e-277e-4fde-9241-6517da658631","url":"https://aisecwatch.com/issues/dbdc380e-277e-4fde-9241-6517da658631","cveId":"CVE-2026-54293","title":"GHSA-p4gq-832x-fm9v: Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read","headline":null,"severity":"high","publishedAt":"2026-06-16T14:34:15.000Z","affected":["nltk@<= 3.9.4"],"epssScore":0.00633,"matchedBy":"ecosystem"},{"id":"5bc9c5ed-cbf7-4d36-81d0-bd2ec7f1d956","url":"https://aisecwatch.com/issues/5bc9c5ed-cbf7-4d36-81d0-bd2ec7f1d956","cveId":"CVE-2026-0847","title":"CVE-2026-0847: A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple…","headline":"NLTK arbitrary file read through path traversal in CorpusReader classes","severity":"high","publishedAt":"2026-03-04T19:16:10.683Z","affected":["nltk@<= 3.9.2"],"epssScore":0.00915,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T22:04:44.925Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}