3.9.4
16 years ago
1 months ago
Known vulnerabilities in the nltk package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Unsafe Dependency Resolution due to lack of verification or sandboxing in the How to fix Unsafe Dependency Resolution? Upgrade | [,3.9.3) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Uncontrolled Recursion via the How to fix Uncontrolled Recursion? Upgrade | [0,3.9.4) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | [0,3.9.4) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Directory Traversal via the XML index file downloader. An attacker can overwrite arbitrary files and create directories at unintended locations by supplying malicious values for the How to fix Directory Traversal? Upgrade | [0,3.9.4) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Missing Authentication for Critical Function in WordNet Browser HTTP server in default configuration. An attacker can cause the service to terminate immediately by sending a specially crafted unauthenticated HTTP GET request (e.g. How to fix Missing Authentication for Critical Function? Upgrade | [0,3.9.4) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Directory Traversal via the Note: This is only exploitable if the function processes untrusted user input, such as in web APIs or network-accessible services. How to fix Directory Traversal? Upgrade | [,3.9.3) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Directory Traversal due to improper sanitization of file paths in the How to fix Directory Traversal? Upgrade | [,3.9.3) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Arbitrary Code Injection via the How to fix Arbitrary Code Injection? Upgrade | [,3.9.3) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Remote Code Execution (RCE) through the integrated data package download functionality. An attacker with control over the NLTK data index can execute arbitrary code by supplying pickled Python code within untrusted packages and trick a user into loading the malicious pickle. Some packages found to be vulnerable if compromised are How to fix Remote Code Execution (RCE)? Upgrade | [0,3.9) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Remote Code Execution (RCE) in the local How to fix Remote Code Execution (RCE)? Upgrade | [,3.8.1) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the local Note: This only affects users of this browser interface to Wordnet, and not other users of Wordnet. How to fix Cross-site Scripting (XSS)? Upgrade | [,3.8.1) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | [0,3.6.6) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via PoC
How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | [0,3.6.6) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) in the How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | [,3.6.4) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS). How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | [0,3.6) |
nltk is a Natural Language Toolkit (NLTK) is a Python package for natural language processing. Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip).
It allows attackers to write arbitrary files via a How to fix Arbitrary File Write via Archive Extraction (Zip Slip)? Upgrade | [,3.4.5) |