Bug 2523556 (CVE-2026-79675) - CVE-2026-79675 nltk: NLTK before 3.10.3 JVM Argument Injection via Per-Call Options
Summary: CVE-2026-79675 nltk: NLTK before 3.10.3 JVM Argument Injection via Per-Call O...
Keywords:
Status: NEW
Alias: CVE-2026-79675
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2528403 2528404
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-25 15:33 UTC by OSIDB Bzimport
Modified: 2026-09-04 05:15 UTC (History)
19 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-25 15:33:20 UTC
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary code execution.


Note You need to log in before you can comment on or make changes to this bug.