
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33230 is a reflected cross-site scripting (XSS) vulnerability in the NLTK WordNet Browser web UI (nltk.app.wordnet_app). An unauthenticated attacker who can convince a user to open a crafted lookup_... URL can execute arbitrary JavaScript in the browser origin of the local WordNet Browser application. All NLTK versions up to and including 3.9.3 are affected; the issue is fixed in version 3.9.4. The vulnerability was published on March 18, 2026, and carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory). IBM products including API Connect and watsonx Orchestrate that bundle NLTK are also affected (IBM Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation). In nltk/app/wordnet_app.py, requests to the lookup_ route are processed by page_from_href(), which calls page_from_reference(Reference.decode(href)). The Reference.decode() function accepts attacker-controlled base64-encoded pickle data from the URL path, and the decoded word value is inserted directly into the HTML response body at line 796 without html.escape(): body = "The word or words '%s' were not found in the dictionary." % word. This is inconsistent with the search route (line 136), which does apply html.escape(). Compounding the risk, the server binds to all interfaces by default (HTTPServer(("", port), ...)) rather than localhost only, making it reachable beyond the local machine (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser context of the WordNet Browser application, enabling manipulation of page content shown to the user, issuance of same-origin requests to other WordNet Browser routes, and triggering of available UI actions within the application. Confidentiality and integrity impacts are low (limited to data accessible within the application's browser origin), and there is no direct availability impact. The primary risk is to users who run nltk.app.wordnet_app as a local or self-hosted HTTP service and can be socially engineered into clicking a malicious link (GitHub Advisory).
A public proof-of-concept (PoC) with step-by-step reproduction instructions — including a Docker setup, a specific base64-encoded pickle payload, and a curl command — is available in the GitHub security advisory. Exploitation has been reported by external sources including a blog post. No threat actor attribution or CISA KEV catalog listing has been identified. The EPSS score is approximately 0.033% (low probability of exploitation in the next 30 days). Exploitation requires user interaction (clicking a crafted link) but no authentication or special privileges (GitHub Advisory).
nltk.app.wordnet_app (WordNet Browser) as a local or network-accessible HTTP service on a known port (default: 8002).("<script>alert(1)</script>", {}) is encoded as: gAWVIQAAAAAAAACMGTxzY3JpcHQ-YWxlcnQoMSk8L3NjcmlwdD6UfZSGlC4=lookup_ route URL, e.g., http://<target>:8002/lookup_gAWVIQAAAAAAAACMGTxzY3JpcHQ-YWxlcnQoMSk8L3NjcmlwdD6UfZSGlC4=/lookup_ followed by a long base64-encoded string (e.g., /lookup_gAWV...); unexpected outbound connections from the browser to attacker-controlled hosts after visiting a WordNet Browser page./lookup_<base64_payload> endpoints with unusually long or URL-safe base64-encoded path segments; HTTP 200 responses to such requests when the word is not found in the dictionary.Upgrade NLTK to version 3.9.4 or later, which applies html.escape() to the word variable in the lookup_ route's "not found" message (commits 1c3f799 and 40d0bc1) (GitHub Commit). For IBM products (API Connect, watsonx Orchestrate), apply the security updates referenced in the respective IBM advisories (IBM Advisory). As a workaround, restrict network access to the WordNet Browser service so it is only reachable from trusted hosts (e.g., bind to localhost only or use a firewall), and avoid opening untrusted links that reference WordNet Browser lookup_ endpoints.
The vulnerability was reported by researcher leduckhuong and published by the NLTK maintainers on March 18, 2026. Red Hat tracked the issue via Bugzilla (Bug 2449825) and assessed it as medium severity. OpenSUSE and Mageia issued security advisories for their packaged versions of python-nltk. IBM issued advisories for affected products (API Connect and watsonx Orchestrate) in May–June 2026. No significant broader media coverage or notable social media discussion beyond standard vulnerability tracking channels was identified (Red Hat Bugzilla, IBM Advisory).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
nltk: 3.2.5-1ubuntu0.1+esm4
devel
nltk
focal (esm-apps)
nltk: 3.4.5-2ubuntu0.1~esm4
jammy
nltk
jammy (esm-apps)
nltk: 3.7-1ubuntu0.1~esm2
noble
nltk
noble (esm-apps)
nltk: 3.8.1-1ubuntu0.1~esm2
resolute
nltk
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."