criticalCVSS 9.8Vulnerability

CVE-2026-79675

## Vulnerability The fix for CVE-2026-12841 (CWE-88, JVM argument injection) added `_validate_java_options()` to block dangerous JVM flags such as `-agentlib`, `-agentpath`, `-javaagent`, `-Xrunjdwp`, and `@argfile` references. However, the validation is only applied when setting global options via `config_java()`. The `java()` function's per-call `options` parameter -- added by PR #3683 (CVE-2026-12615 fix) -- passes options directly to `subprocess.Popen` without calling `_validate_java_options()`. All four Stanford Java wrapper classes accept user-supplied `java_options` and route them through the unvalidated per-call path, bypassing the CVE-2026-12841 fix entirely. ## Root Cause In `nltk/internals.py`, the `java()` function (line 128) accepts an `options` keyword argument. When `options` is not None, it is converted to a list and prepended to the JVM command (lines 211-217) without any validation: ```python # nltk/internals.py, lines 211-217 (HEAD) if options is None: java_options = _java_options # validated by config_java() else: if isinstance(options, str): options = options.split() java_options = list(options) # NO validation cmd = [_java_bin] + java_options + cmd ``` Compare with `config_java()` (line 92) which does validate: ```python # nltk/internals.py, lines 122-123 _validate_java_options(options) _java_options[:] = options ``` The four affected wrapper classes store user-supplied `java_options` without validation and pass them through the unvalidated per-call path: 1. `GenericStanfordParser` (`nltk/parse/stanford.py`): constructor parameter at line 39, stored at line 78, passed at lines 247 and 256 2. `StanfordTagger` (`nltk/tag/stanford.py`): constructor parameter at line 51, stored at line 79, passed at line 118 3. `StanfordTokenizer` (`nltk/tokenize/stanford.py`): constructor parameter at line 43, stored at line 66, passed at line 109 4. `StanfordSegmenter` (`nltk/tokenize/stanford_segmenter.py`): constructor p

Properties

ghsa_id
GHSA-m4rf-3fr8-xwx3
severity
critical
summary
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
cvss_score
9.8
cve_id
CVE-2026-79675
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
is_ghsa_only
false
ghsa_published
2026-09-01T20:38:22Z
source_url
https://github.com/advisories/GHSA-m4rf-3fr8-xwx3
ghsa_updated
2026-09-01T20:38:23Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]pip/nltk

AFFECTS (1)

[Software]pip/nltk

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-79675 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal