CVE-2024-39705: NLTK through 3.8.1 allows remote code execution if untrusted packages ...

Severity: Critical

CVSS Score: 7.5

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.