Skip to content

CVE lookup

CVE-2026-71513

Pruva has a verified reproduction for CVE-2026-71513: NLTK <3.10.3 RCE in AllowlistUnpickler — validates pickle module string but not global name; dotted-name traversal escapes allowlist to reach arbitrary callables. The canonical evidence record is REPRO-2026-00336.

REPRO

REPRO-2026-00336

Package

nltk/nltk · github

Severity

HIGH

Status

published