CVE-2026-33230: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-33230 is a reflected cross-site scripting (XSS) vulnerability in the NLTK WordNet Browser web UI (nltk.app.wordnet_app). An unauthenticated attacker who can convince a user to open a crafted lookup_... URL can execute arbitrary JavaScript in the browser origin of the local WordNet Browser application. All NLTK versions up to and including 3.9.3 are affected; the issue is fixed in version 3.9.4. The vulnerability was published on March 18, 2026, and carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory). IBM products including API Connect and watsonx Orchestrate that bundle NLTK are also affected (IBM Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation). In nltk/app/wordnet_app.py, requests to the lookup_ route are processed by page_from_href(), which calls page_from_reference(Reference.decode(href)). The Reference.decode() function accepts attacker-controlled base64-encoded pickle data from the URL path, and the decoded word value is inserted directly into the HTML response body at line 796 without html.escape(): body = "The word or words '%s' were not found in the dictionary." % word. This is inconsistent with the search route (line 136), which does apply html.escape(). Compounding the risk, the server binds to all interfaces by default (HTTPServer(("", port), ...)) rather than localhost only, making it reachable beyond the local machine (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser context of the WordNet Browser application, enabling manipulation of page content shown to the user, issuance of same-origin requests to other WordNet Browser routes, and triggering of available UI actions within the application. Confidentiality and integrity impacts are low (limited to data accessible within the application's browser origin), and there is no direct availability impact. The primary risk is to users who run nltk.app.wordnet_app as a local or self-hosted HTTP service and can be socially engineered into clicking a malicious link (GitHub Advisory).

Exploitability

A public proof-of-concept (PoC) with step-by-step reproduction instructions — including a Docker setup, a specific base64-encoded pickle payload, and a curl command — is available in the GitHub security advisory. Exploitation has been reported by external sources including a blog post. No threat actor attribution or CISA KEV catalog listing has been identified. The EPSS score is approximately 0.033% (low probability of exploitation in the next 30 days). Exploitation requires user interaction (clicking a crafted link) but no authentication or special privileges (GitHub Advisory).

Exploitation steps

  1. Identify a target: Confirm the victim is running nltk.app.wordnet_app (WordNet Browser) as a local or network-accessible HTTP service on a known port (default: 8002).
  2. Craft the malicious payload: Create a base64-encoded pickle object containing the desired JavaScript payload. For example, the tuple ("<script>alert(1)</script>", {}) is encoded as: gAWVIQAAAAAAAACMGTxzY3JpcHQ-YWxlcnQoMSk8L3NjcmlwdD6UfZSGlC4=
  3. Construct the malicious URL: Embed the encoded payload in a lookup_ route URL, e.g., http://<target>:8002/lookup_gAWVIQAAAAAAAACMGTxzY3JpcHQ-YWxlcnQoMSk8L3NjcmlwdD6UfZSGlC4=
  4. Deliver the link: Send the crafted URL to the victim via email, chat, or any social engineering channel and convince them to open it in their browser while the WordNet Browser service is running.
  5. JavaScript executes: The server decodes the pickle payload, extracts the word (containing the script tag), and reflects it unescaped into the HTML response. The victim's browser renders the page and executes the injected JavaScript in the WordNet Browser's origin, enabling session manipulation, same-origin requests, or further exploitation (GitHub Advisory).

Indicators of compromise

  • Network: HTTP GET requests to the WordNet Browser service (default port 8002) with paths matching /lookup_ followed by a long base64-encoded string (e.g., /lookup_gAWV...); unexpected outbound connections from the browser to attacker-controlled hosts after visiting a WordNet Browser page.
  • Logs: Web server access logs showing requests to /lookup_<base64_payload> endpoints with unusually long or URL-safe base64-encoded path segments; HTTP 200 responses to such requests when the word is not found in the dictionary.
  • File System: No direct file system artifacts expected for reflected XSS; however, if the XSS is used to trigger further actions, look for unexpected files written by the browser or application process.
  • Process: Unexpected child processes or network connections spawned from the browser process after a user visits a crafted WordNet Browser URL (GitHub Advisory).

Mitigation and workarounds

Upgrade NLTK to version 3.9.4 or later, which applies html.escape() to the word variable in the lookup_ route's "not found" message (commits 1c3f799 and 40d0bc1) (GitHub Commit). For IBM products (API Connect, watsonx Orchestrate), apply the security updates referenced in the respective IBM advisories (IBM Advisory). As a workaround, restrict network access to the WordNet Browser service so it is only reachable from trusted hosts (e.g., bind to localhost only or use a firewall), and avoid opening untrusted links that reference WordNet Browser lookup_ endpoints.

Community reactions

The vulnerability was reported by researcher leduckhuong and published by the NLTK maintainers on March 18, 2026. Red Hat tracked the issue via Bugzilla (Bug 2449825) and assessed it as medium severity. OpenSUSE and Mageia issued security advisories for their packaged versions of python-nltk. IBM issued advisories for affected products (API Connect and watsonx Orchestrate) in May–June 2026. No significant broader media coverage or notable social media discussion beyond standard vulnerability tracking channels was identified (Red Hat Bugzilla, IBM Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

nltk

Affected

sid

nltk: 3.10.0-1

Fixed

trixie

nltk

Affected

Ubuntu

Fixed

bionic (esm-apps)

nltk: 3.2.5-1ubuntu0.1+esm4

Fixed

devel

nltk

Affected

focal (esm-apps)

nltk: 3.4.5-2ubuntu0.1~esm4

Fixed

jammy

nltk

Affected

jammy (esm-apps)

nltk: 3.7-1ubuntu0.1~esm2

Fixed

noble

nltk

Affected

noble (esm-apps)

nltk: 3.8.1-1ubuntu0.1~esm2

Fixed

resolute

nltk

Affected

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management