漏洞情报聚合

CVE-2026-71513 - NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the model through allowlisted_pickle_load. - 漏洞详情

漏洞编号:CVE-2026-71513

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-71513

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-502

发布/更新时间:2026-08-22 / 2026-08-27

漏洞描述

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace. Attackers can craft untrusted transition-parser models that execute arbitrary commands when TransitionParser.parse loads the model through allowlisted_pickle_load.

相关链接

相关漏洞

« 返回首页