NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perceptron_tagger and punkt.
"https://github.com/pypa/advisory-database/blob/main/vulns/nltk/PYSEC-2024-167.yaml"