CVE-2026-0848 is a critical arbitrary code execution vulnerability affecting NLTK versions up to 3.9.2, specifically within the StanfordSegmenter module. This flaw stems from improper input validation that allows unverified Java .jar files to be loaded and executed, enabling attackers to run arbitrary Java bytecode. With a CVSS score of 10.0, this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no active exploits or public exploit code are currently identified, and community discussion is minimal, the potential for remote code execution makes this a severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.9.2CPE matchmatch criteria | cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.