CVE-2024-39705: Nltk

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.

Affected products

  • Nltk Nltk: up to and including 3.8.1

Published 2024-06-27. Last modified 2026-06-17.