THREAT OPS › Threat News › [GHSA] GHSA-m4rf-3fr8-xwx3 (critical) — NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
[GHSA] GHSA-m4rf-3fr8-xwx3 (critical) — NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
GHSA-m4rf-3fr8-xwx3 Severity: critical CVE: CVE-2026-79675
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
## Vulnerability
The fix for CVE-2026-12841 (CWE-88, JVM argument injection) added `_validate_java_options()` to block dangerous JVM flags such as `-agentlib`, `-agentpath`, `-javaagent`, `-Xrunjdwp`, and `@argfile`
Indicators of compromise
- CVE-2026-12841cve
- CVE-2026-79675cve
- CVE-2026-12615cve
Original source: https://github.com/advisories/GHSA-m4rf-3fr8-xwx3