Deserialization of Untrusted Data in Natural Language Toolkit - #VU141419

 

Deserialization of Untrusted Data in Natural Language Toolkit - #VU141419

Published: August 11, 2026


Vulnerability identifier: #VU141419
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to deserialization of untrusted data in TransitionParser.parse() when loading a user-supplied model file. A remote attacker can supply a specially crafted pickle file to execute arbitrary code.

User interaction is required to load the crafted model file.


Affected software

Natural Language Toolkit

Remediation

Install security update from vendor's website.

Natural Language Toolkit - update to 3.10.0

External References

Related Security Bulletins