THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x99w-6fgc-pmfw (critical) — NLTK: Allowlisted pickle loaders still permit code execution in current source

[GHSA] GHSA-x99w-6fgc-pmfw (critical) — NLTK: Allowlisted pickle loaders still permit code execution in current source

medgithub_advisoriesPublished 2026-09-08

GHSA-x99w-6fgc-pmfw Severity: critical CVE: CVE-2026-79657

NLTK: Allowlisted pickle loaders still permit code execution in current source

### Summary

The current source tree still allows arbitrary code execution during supposedly safer allowlisted pickle loading. The allowlist trusts whole module namespaces instead of exact safe globals, so crafted pickles can invoke dangerous in-namespace call

Indicators of compromise

Original source: https://github.com/advisories/GHSA-x99w-6fgc-pmfw