THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-m4rf-3fr8-xwx3 (critical) — NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)

[GHSA] GHSA-m4rf-3fr8-xwx3 (critical) — NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)

medgithub_advisoriesPublished 2026-09-01

GHSA-m4rf-3fr8-xwx3 Severity: critical CVE: CVE-2026-79675

NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)

## Vulnerability

The fix for CVE-2026-12841 (CWE-88, JVM argument injection) added `_validate_java_options()` to block dangerous JVM flags such as `-agentlib`, `-agentpath`, `-javaagent`, `-Xrunjdwp`, and `@argfile`

Indicators of compromise

Original source: https://github.com/advisories/GHSA-m4rf-3fr8-xwx3