Vulnerability record · CVE-2025-71408 · published 24 July 2026
CVE-2025-71408: Nltk vulnerability
Nltk · Nltk
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.
Description
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://aydinnyunus.github.io/2026/06/07/command-injection-nltk-collocations-eval/ | ExploitPress/Media CoverageThird Party Advisory |
| https://github.com/nltk/nltk/commit/66f14096d952ec8f04934f515e027534bd4eb0ac | Patch |
| https://github.com/nltk/nltk/pull/3465 | Issue TrackingPatch |
| https://github.com/nltk/nltk/releases/tag/3.9.3 | Release Notes |
| https://www.vulncheck.com/advisories/nltk-eval-injection-via-collocations-py-command-line-arguments | PatchThird Party Advisory |
Track CVE-2025-71408 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-71408), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.