CVE lookup
CVE-2026-71513
Pruva has a verified reproduction for CVE-2026-71513: NLTK <3.10.3 RCE in AllowlistUnpickler — validates pickle module string but not global name; dotted-name traversal escapes allowlist to reach arbitrary callables. The canonical evidence record is REPRO-2026-00336.
REPRO
REPRO-2026-00336
Package
nltk/nltk · github
Severity
HIGH
Status
published