NLTK addressed multiple pickle deserialization weaknesses that could let attackers execute arbitrary Python code by supplying malicious model files. An advisory said versions up to 3.9.4 were vulnerable in TransitionParser.parse(), where pickle_load() used an unsafe path that allowed arbitrary class resolution during deserialization; the issue was fixed in NLTK 3.10.0. The project had already introduced safer loaders in picklesec.py, including RestrictedUnpickler, WarningUnpickler, and AllowlistUnpickler, and warned that pickle files should be loaded only from trusted sources.
A later hardening update tightened those protections after bypasses were identified in the allowlist logic. The patch closed remote-code-execution paths by rejecting dotted names, blocking dangerous module prefixes, denying specific risky globals and dunder names, and replacing broad module-prefix allowlists for Punkt model loading with exact global allowlists. The changes specifically targeted gadget access through objects such as sklearn.os.system, numpy.f2py.crackfortran.myeval, nltk.tokenize.repp.ReppTokenizer._execute, and numpy.load, while regression tests were added to ensure malicious payloads are blocked and legitimate NLTK and scientific-stack objects still deserialize correctly.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
NLTK disclosed four vulnerabilities affecting versions before 3.10.3, including two critical pickle deserialization flaws plus an XML entity expansion DoS issue and an SSRF issue in proxy handling. The disclosure states all four issues are fixed in NLTK 3.10.3 and recommends upgrading, with no known active exploitation reported at the time.
On August 11, 2026, NLTK committed additional hardening to close pickle deserialization bypasses tracked as GHSA-4489 and GHSA-x99w. The patch blocked dotted-name traversal, denied dangerous module prefixes and globals, rejected dunder names, and replaced Punkt's broad module-prefix allowlist with exact allowed globals.
On July 1, 2026, NLTK introduced `picklesec.py` and a security fix labeled `fix(security): prevent pickle RCE in TransitionParser model loading`. The change added `RestrictedUnpickler`, `WarningUnpickler`, `AllowlistUnpickler`, and helper loaders intended to reduce arbitrary code execution risk from pickle files.
A vulnerability affecting NLTK versions up to 3.9.4 was fixed in NLTK 3.10.0. The flaw was in `TransitionParser.parse()`, which used `pickle_load()` with `restricted=false`, allowing arbitrary class resolution through `WarningUnpickler` and enabling code execution via malicious model files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcevulncheck.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.