What is CVE-2025-71408?
CVE-2025-71408 is an eval injection vulnerability in the nltk.collocations module of NLTK before version 3.9.3. An attacker controlling command-line arguments can execute arbitrary Python code when collocations.py is run directly. Upgrading to version 3.9.3 or later is advised to mitigate the risk.
Azərbaycanca: CVE-2025-71408, NLTK kitabxanasının 3.9.3-dən əvvəlki versiyalarında "nltk.collocations" modulunda eval injection zəifliyidir. Əmr sətiri arqumentlərini idarə edən hücumçuya ixtiyari Python kodu icra etməyə imkan verir. Təsirə məruz qalmamaq üçün kitabxananı ən az 3.9.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ1
To which version should NLTK be upgraded to mitigate CVE-2025-71408?
It is advised to upgrade the NLTK library to version 3.9.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.