CVE-2025-71408 - NLTK < 3.9.2 Eval Injection via collocations.py Command-Line Arguments
Summary
This entry details a vulnerability found in the target system. The exploit was published on 2026-08-02 and has garnered 8 views from the community. It is classified under the remote category. Users are advised to review the source code in the Detail tab for technical specifics.
Zafiyet Ozet Bilgileri
Zafiyet Detayı (Turkce)
Sürüm 3.9.3'ten önceki NLTK (Doğal Dil Araç Takımı), nltk.collocations modülünde, komut satırı bağımsız değişkenlerini kontrol eden bir saldırganın rastgele Python kodu yürütmesine olanak tanıyan bir değerlendirme enjeksiyon güvenlik açığı içerir. collocations.py doğrudan çağrıldığında, __main__ bloğu komut satırı argümanlarını izin verilenler listesi doğrulaması olmadan BigramAssocMeasures'ın son ekleri olarak doğrudan eval()'a iletir…
Orijinal Aciklama (Ingilizce)
CVE ID, Product, Vendor ... Pricing Browse by Apps View All Apps Splunk Slack Webhook Teams Jira Chrome API