OSV 1.4.0 · github-reviewed · 修改于 2026-09-02 22:41
发布时间
2026-08-25 20:31
GitHub 审查时间
2026-09-02 22:41
NVD 发布时间
2026-08-25 20:16
源文件
advisories/github-reviewed/2026/08/GHSA-vp9c-2pjm-8925/GHSA-vp9c-2pjm-8925.json
该公告已于 2026-09-02 22:41 撤回
内容仅用于保留外部引用,请不要将其当作仍然有效的安全结论。
This advisory has been withdrawn because it is a duplicate of GHSA-x99w-6fgc-pmfw. This link is maintained to preserve external references.
NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace functions like ReppTokenizer._execute and numpy.f2py.crackfortran.myeval through pickle REDUCE to execute arbitrary commands during model or tokenizer artifact loading.