Reflected Cross-Site Scripting Vulnerability in NLTK by Python Software Foundation
CVE-2026-33230
What is CVE-2026-33230?
NLTK (Natural Language Toolkit) versions 3.9.3 and earlier are vulnerable to a reflected cross-site scripting (XSS) flaw in the nltk.app.wordnet_app. Through a specially crafted lookup_<payload> URL, an attacker can inject arbitrary HTML or JavaScript into the response page. This occurs because unsanitized user input for the word parameter is reflected back into the HTML output. Such exploitation poses a risk for users operating the local WordNet Browser server, as it may allow execution of unwanted scripts within the browser context of the application. The issue has been addressed in the subsequent updates, marking an essential step in securing NLTK applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
nltk <= 3.9.3
