NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| nltk(PyPI) | 0 | 3.9 | N/A |
CVSS Metrics