Vulnerability PYSEC-2026-3868
Summary
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
Details
Two NLTK sites executed the Graphviz dot program by bare name, so process creation resolved it via the search path — and on Windows via the current working directory — rather than a validated absolute location. An attacker who can place a file named dot where resolution looks (the CWD on Windows, or a writable/relative entry such as . on PATH) has their binary executed in place of Graphviz (arbitrary code execution).
Affected (<= 3.10.2):
nltk.parse.dependencygraph.dot2img— calledfind_binary("dot")but discarded the returned validated path and then ran the bare name["dot", ...], so the validation had no effect.nltk.translate.api.AlignedSent._repr_svg_— ran the bare name with no validation at all (IPython SVG rendering).
This is the same class already fixed for the senna, weka, boxer, malt, repp and hunpos wrappers. nltk.internals.find_binary refuses a CWD-relative match for a bare tool name and returns only a trusted absolute path; the fix runs that path in both sites.
Related Vulnerabilities
Other vulnerabilities affecting the same packages