THREAT OPS › Threat News › [GHSA] GHSA-x99w-6fgc-pmfw (critical) — NLTK: Allowlisted pickle loaders still permit code execution in current source
[GHSA] GHSA-x99w-6fgc-pmfw (critical) — NLTK: Allowlisted pickle loaders still permit code execution in current source
GHSA-x99w-6fgc-pmfw Severity: critical CVE: CVE-2026-79657
NLTK: Allowlisted pickle loaders still permit code execution in current source
### Summary
The current source tree still allows arbitrary code execution during supposedly safer allowlisted pickle loading. The allowlist trusts whole module namespaces instead of exact safe globals, so crafted pickles can invoke dangerous in-namespace call
Indicators of compromise
- CVE-2026-79657cve
Original source: https://github.com/advisories/GHSA-x99w-6fgc-pmfw