Summary
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Vulnerability
The fix for CVE-2026-12841 (CWE-88, JVM argument injection) added _validate_java_options() to block dangerous JVM flags such as -agentlib, -agentpath, -javaagent, -Xrunjdwp, and @argfile references. However, the validation is only applied when setting global options via config_java(). The java() function's per-call options parameter -- added by PR #3683 (CVE-2026-12615 fix) -- passes options directly to subprocess.Popen without calling _validate_java_options().
All four Stanford Java wrapper classes accept user-supplied java_options and route them through the unvalidated per-call path, bypassing the CVE-2026-12841 fix entirely.
Root Cause
In nltk/internals.py, the java() function (line 128) accepts an options keyword argument. When options is not None, it is converted to a list and prepended to the JVM command (lines 211-217) without any validation:
# nltk/internals.py, lines 211-217 (HEAD)
if options is None:
java_options = _java_options # validated by config_java()
else:
if isinstance(options, str):
options = options.split()
java_options = list(options) # NO validation
cmd = [_java_bin] + java_options + cmd
Compare with config_java() (line 92) which does validate:
# nltk/internals.py, lines 122-123
_validate_java_options(options)
_java_options[:] = options
The four affected wrapper classes store user-supplied java_options without validation and pass them through the unvalidated per-call path:
GenericStanfordParser(nltk/parse/stanford.py): constructor parameter at line 39, stored at line 78, passed at lines 247 and 256StanfordTagger(nltk/tag/stanford.py): constructor parameter at line 51, stored at line 79, passed at line 118StanfordTokenizer(nltk/tokenize/stanford.py): constructor parameter at line 43, stored at line 66, passed at line 109StanfordSegmenter(nltk/tokenize/stanford_segmenter.py): constructor parameter at line 68, stored at line 117, passed at line 337
Proof of Concept
from nltk.internals import config_java, java, _validate_java_options
# 1. The global config_java() path correctly blocks dangerous flags:
try:
config_java(options=["-agentpath:/tmp/evil.so"])
except ValueError as e:
print(f"config_java blocked: {e}") # blocked as expected
# 2. The per-call options path does NOT block them:
# (Would execute if Java were installed)
# java(["SomeClass"], classpath=".", options=["-agentpath:/tmp/evil.so"])
# This passes "-agentpath:/tmp/evil.so" directly to subprocess.Popen
# 3. Stanford wrapper classes pass through without validation:
# from nltk.parse.stanford import StanfordParser
# parser = StanfordParser(java_options="-agentpath:/tmp/evil.so")
# parser.parse(...) # dangerous flag reaches JVM
# Verify the gap directly:
dangerous_opts = ["-agentpath:/tmp/evil.so"]
try:
_validate_java_options(dangerous_opts)
print("Would have been caught")
except ValueError:
print("Correctly rejected by _validate_java_options()")
# But java() itself never calls _validate_java_options():
import inspect
source = inspect.getsource(java)
assert "_validate_java_options" not in source, "java() does not validate options"
print("Confirmed: java() does not call _validate_java_options()")
AI tooling
AI assistance was used for the code audit and for drafting this report. The finding were manually verified against the project's source at the location cited above before reporting it, and the severity and impact assessment are the reporters.
Impact
An attacker who controls the java_options parameter to any NLTK Stanford wrapper class can inject arbitrary JVM flags, including:
-agentpath:/path/to/malicious.so-- loads a native agent, achieving arbitrary code execution-javaagent:/path/to/malicious.jar-- loads a Java agent for bytecode manipulation-agentlib:jdwp=transport=dt_socket,server=y,address=*:5005-- enables remote debugging, allowing remote code execution@/path/to/argfile-- expands an argument file, which can smuggle any of the above
This is exploitable in scenarios where NLTK is deployed as a service and java_options is derived from user input, configuration files, or environment variables. The PR #3647 commit message explicitly states the fix was intended to cover "StanfordSegmenter, and GenericStanfordParser" but the implementation only validates in config_java().
CVE-2026-79675 has a CVSS score of 9.8 (Critical). The vector is network-reachable, no privileges required, and no user interaction. A CVSS score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether this affects your application depends on whether the vulnerable code is present and reachable in your environment. A fixed version is available (3.10.3); upgrading removes the vulnerable code path.
Affected versions
Security releases
Kodem intelligence
Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.
Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.
Already deployed Kodem?
See it in your environmentNew to Kodem? Get a demo →Remediation advice
Add _validate_java_options() to the java() function's per-call options handling:
# nltk/internals.py, in the java() function
if options is None:
java_options = _java_options
else:
if isinstance(options, str):
options = options.split()
java_options = list(options)
_validate_java_options(java_options) # ADD THIS LINE
cmd = [_java_bin] + java_options + cmd
This single-line addition closes the bypass for all four Stanford wrapper classes and any future callers of java(options=...).
Frequently Asked Questions
- What is CVE-2026-79675? CVE-2026-79675 is a critical-severity security vulnerability in nltk (pip), affecting versions <= 3.10.2. It is fixed in 3.10.3.
- How severe is CVE-2026-79675? CVE-2026-79675 has a CVSS score of 9.8 (Critical). This score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether it represents real risk in your environment depends on whether the vulnerable code is present and reachable.
- Which versions of nltk are affected by CVE-2026-79675? nltk (pip) versions <= 3.10.2 is affected.
- Is there a fix for CVE-2026-79675? Yes. CVE-2026-79675 is fixed in 3.10.3. Upgrade to this version or later.
- Is CVE-2026-79675 exploitable, and should I be worried? Whether CVE-2026-79675 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
- What actually determines whether CVE-2026-79675 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
- How do I fix CVE-2026-79675? Upgrade
nltkto 3.10.3 or later.