CVE-2026-12252: CWE-94 Improper Control of Generation of Code in nltk nltk/nltk
In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These classes accept user-controllable JAR paths and execute them via the `java()` function, which invokes `subprocess.Popen()` without integrity verification. This vulnerability is identical to CVE-2026-0848, which was fixed for StanfordSegmenter by adding SHA256 verification. However, the fix was not applied to these additional classes, leaving them susceptible to arbitrary code execution when loading untrusted JAR files.
AI Analysis
Technical Summary
CVE-2026-12252 affects nltk/nltk versions up to 3.9.3 in five Stanford interface classes: StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser. These classes accept user-controlled JAR file paths and execute them using the java() function, which internally calls subprocess.Popen() without verifying the integrity of the JAR files. This lack of verification enables an attacker to execute arbitrary code by supplying malicious JAR files. The vulnerability is identical in nature to CVE-2026-0848, which was fixed for the StanfordSegmenter class by adding SHA256 verification of JAR files. However, the fix was not extended to these other classes, leaving them vulnerable.
Potential Impact
Successful exploitation can lead to arbitrary code execution on the host system with the privileges of the user running the nltk process. This can compromise confidentiality, integrity, and availability of the affected system. The CVSS score of 7.8 (high) reflects the significant impact and the low attack complexity, although user interaction is required.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, users should avoid loading untrusted JAR files with the affected Stanford interface classes. Applying the SHA256 verification approach used in CVE-2026-0848 to these classes is recommended once a patch is available.
CVE-2026-12252: CWE-94 Improper Control of Generation of Code in nltk nltk/nltk
Description
In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These classes accept user-controllable JAR paths and execute them via the `java()` function, which invokes `subprocess.Popen()` without integrity verification. This vulnerability is identical to CVE-2026-0848, which was fixed for StanfordSegmenter by adding SHA256 verification. However, the fix was not applied to these additional classes, leaving them susceptible to arbitrary code execution when loading untrusted JAR files.
CVSS v3.0
Score 7.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-12252 affects nltk/nltk versions up to 3.9.3 in five Stanford interface classes: StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser. These classes accept user-controlled JAR file paths and execute them using the java() function, which internally calls subprocess.Popen() without verifying the integrity of the JAR files. This lack of verification enables an attacker to execute arbitrary code by supplying malicious JAR files. The vulnerability is identical in nature to CVE-2026-0848, which was fixed for the StanfordSegmenter class by adding SHA256 verification of JAR files. However, the fix was not extended to these other classes, leaving them vulnerable.
Potential Impact
Successful exploitation can lead to arbitrary code execution on the host system with the privileges of the user running the nltk process. This can compromise confidentiality, integrity, and availability of the affected system. The CVSS score of 7.8 (high) reflects the significant impact and the low attack complexity, although user interaction is required.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, users should avoid loading untrusted JAR files with the affected Stanford interface classes. Applying the SHA256 verification approach used in CVE-2026-0848 to these classes is recommended once a patch is available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- @huntr_ai
- Date Reserved
- 2026-06-15T08:33:00.274Z
- Cvss Version
- 3.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a48673727e9c79719a1829d
Added to database: 07/04/2026, 01:51:51 UTC
Last enriched: 07/11/2026, 08:55:32 UTC
Last updated: 08/18/2026, 00:41:10 UTC
Views: 149
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.