CVE-2025-71408
NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to execute arbitrary Python code. When collocations.py is invoked directly, the __main__ block passes command-line arguments directly to eval() as suffixes of BigramAssocMeasures without allowlist validation or sanitization, enabling an attacker to supply a Python expression that escapes the intended attribute lookup and executes arbitrary code including OS commands via the os module.
- Affected products
- Nltk
- Fix
- Available
- CVSS 4.0
- 8.5 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.2% (5th percentile)
- Weakness
- CWE-95
- NVD status
- Undergoing Analysis
- Published
- 2026-07-24
No indexed exploits for CVE-2025-71408 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-71408 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.