CVE-2024-39705
Last modified
CVE-2024-39705 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.. EPSS estimates a 1.35% chance of exploitation in the next 30 days.
Description
NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-39705?
How severe is CVE-2024-39705?
How do I fix CVE-2024-39705?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-3970Server Side Request Forgery vulnerability has been discovere…7.5
- CVE-2024-39700JupyterLab extension template is a `copier` template for Ju…9.8
- CVE-2024-39701Directus is a real-time API and App dashboard for managing S…7.7
- CVE-2024-39702In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the…5.9
- CVE-2024-39703In ThreatQuotient ThreatQ before 5.29.3, authenticated users…8.8
- CVE-2024-39704Soft Circle French-Bread Melty Blood: Actress Again: Current…9.8
- CVE-2024-39707Insyde IHISI function 0x49 can restore factory defaults for …5.3
- CVE-2024-39708An issue was discovered in the Agent in Delinea Privilege Ma…7
- CVE-2024-39709Incorrect file permissions in Ivanti Connect Secure before v…7.8
- CVE-2024-3971The Similarity WordPress plugin through 3.0 does not have CS…4.3
- CVE-2024-39710Argument injection in Ivanti Connect Secure before version 2…9.1
- CVE-2024-39711Argument injection in Ivanti Connect Secure before version 2…9.1
Are you affected by CVE-2024-39705?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
