THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6hwm-xvph-95vm (high) — NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

[GHSA] GHSA-6hwm-xvph-95vm (high) — NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

medgithub_advisoriesPublished 2026-09-01

GHSA-6hwm-xvph-95vm Severity: high CVE: CVE-2026-78680

NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary

Two NLTK sites executed the Graphviz `dot` program by bare name, so process creation resolved it via the search path — and on Windows via the current working directory — rather than a validated absolute location. An attacker who can place a file named `dot` where resoluti

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6hwm-xvph-95vm