HIGH
NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary
Published Aug 25, 2026
8.5
HIGHCVSS 4.0
EPSS 0.18%
Description
NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary in the search path or current working directory. Attackers can exploit bare-name binary resolution on Windows via the current working directory or on Unix-like systems via relative PATH entries to execute their binary instead of the legitimate Graphviz tool.
Affected products
-
- Version 0StatusaffectedConstraints<3.10.3
- Version 3.10.3StatusunaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-65226 Advisory
- https://github.com/advisories/GHSA-6hwm-xvph-95vm Advisory
- https://github.com/nltk/nltk/commit/1a3cd1764ab3deb084fb66d0ffb4873717659538
- https://github.com/nltk/nltk/releases/tag/v3.10.3
- https://github.com/nltk/nltk/security/advisories/GHSA-6hwm-xvph-95vm exploitvendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-78680
- https://www.vulncheck.com/advisories/nltk-before-arbitrary-code-execution-via-graphviz-dot-binary third-party-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 25, 2026
Updated Aug 25, 2026
Reserved Aug 25, 2026
Link CVE-2026-78680
CISA Vulnrichment
Updated Aug 25, 2026
ENISA EUVD
EUVD-2026-65226 GHSA-6HWM-XVPH-95VM Assigner VulnCheck
Published Aug 25, 2026
Updated Aug 25, 2026
Exploited since n/a
Link EUVD-2026-65226