GHSA-x99w-6fgc-pmfw: NLTK: Allowlisted pickle loaders still permit code execution in current source
HIGHCritical vulnerability
What to do
- Critical severity — schedule an urgent patch.
### Summary The current source tree still allows arbitrary code execution during supposedly safer allowlisted pickle loading. The allowlist trusts whole module namespaces instead of exact safe globals, so crafted pickles can invoke dangerous in-namespace callables through pickle REDUCE. …
CVE · detail
- CVE-2026-79657nvd ↗EPSS 1%
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected