Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2022-21797 The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary ...CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code ExecutionCVE-2021-3828 nltk is vulnerable to Inefficient Regular Expression ComplexityCVE-2021-3842 nltk is vulnerable to Inefficient Regular Expression ComplexityCVE-2021-43854 NLTK (Natural Language Toolkit) is a suite of open source Python modul ...CVE-2024-39705 NLTK through 3.8.1 allows remote code execution if untrusted packages ...CVE-2026-0846 nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` functionCVE-2026-12061 Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regexCVE-2026-12072 Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)CVE-2026-12074 Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)CVE-2026-12075 Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE modeCVE-2026-33231 nltk: NLTK: Denial of Service via unauthenticated remote shutdownCVE-2026-54293 nltk: NLTK: Information Disclosure via Path Traversal in `nltk.data.load()`CVE-2026-33230 nltk: NLTK: Script execution via reflected cross-site scripting in WordNet BrowserCVE-2021-41495 numpy: NULL pointer dereference in numpy.sort in in the PyArray_DescrNew() due to missing return-value validationCVE-2021-33430 numpy: buffer overflow in the PyArray_NewFromDescr_int() in ctors.cCVE-2021-34141 numpy: incomplete string comparison in the numpy.core componentCVE-2021-41496 numpy: buffer overflow in the array_from_pyobj() in fortranobject.cCVE-2024-5629 python-pymongo: Out-of-bounds read in bson moduleCVE-2024-34062 python-tqdm: non-boolean CLI arguments may lead to local code executionYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2022-288 The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.PYSEC-2026-96 A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path PYSEC-2026-99 NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verificPYSEC-2026-2132 Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.PYSEC-2021-356 nltk is vulnerable to Inefficient Regular Expression ComplexityPYSEC-2021-859 NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Versions prior to 3.6.5 are vulnePYSEC-2022-5 nltk is vulnerable to Inefficient Regular Expression ComplexityPYSEC-2024-167 NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_percPYSEC-2026-2078 NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.loPYSEC-2026-2085 In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerPYSEC-2026-2235 NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltPYSEC-2026-2236 NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltPYSEC-2026-2237 NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the PYSEC-2026-3581 Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)PYSEC-2026-3582 Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regexPYSEC-2026-3583 Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE modePYSEC-2026-3584 Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)PYSEC-2026-597 NLTK version 3.9.4 is vulnerable to a path traversal attack due to an incomplete fix for GitHub Issue #3504. The `_UNSAFE_NO_PROTOCOL_RE` regex in `nltk/data.py` checks for literal `../` sequences butPYSEC-2026-97 A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files sPYSEC-2026-98 A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BrackGHSA-rf74-v2fm-23pw Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoSPYSEC-2021-856 Null Pointer Dereference vulnerability exists in numpy.sort in NumPy < and 1.19 in the PyArray_DescrNew function due to missing return-value validation, which allows attackers to conduct DoS attacksPYSEC-2021-857 Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a Denial of Service attacks by carefully constructing an array with negative valuGHSA-6p56-wp2h-9hxr NumPy Buffer Overflow (Disputed)GHSA-fpfv-jqm9-f5jm Incorrect Comparison in NumPyCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.