CVE-2026-79675
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to achieve arbitrary code execution.
- Affected products
- Nltk
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.4% (33th percentile)
- Weakness
- CWE-88
- NVD status
- Received
- Published
- 2026-08-25
CVE-2026-79675 at NVD
1 known exploit for CVE-2026-79675
Proof-of-concept code and exploit modules indexed by Sploitus