PyPI: nltk

CVE-2026-12252

Safety vulnerability ID: SFTY-20260704-39717

Affected versions of the `nltk` package are vulnerable to Code Injection due to executing user-controllable JAR files without integrity verification. The Stanford interface classes `StanfordPOSTagger`, `StanfordNERTagger`, `StanfordParser`, `StanfordDependencyParser` and `StanfordNeuralDependencyParser` accept a JAR path and run it through the `java()` function, which calls `subprocess.Popen()` without the SHA256 verification already added to `StanfordSegmenter` for CVE-2026-0848. An attacker who can influence the JAR path an application loads, or substitute the JAR file, can execute arbitrary code with the privileges of the process using these classes.

Created at: Oct 2, 2026Updated at: Oct 2, 2026

Overview

NLTK Stanford wrapper classes execute untrusted JAR files without verification

Advisory

nltk – Code Injection

Affected Package

Affecting nltk package, versions< 3.9.4

Also affects

---

How to Fix

Upgradenltkto3.9.4or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more