My team's dependabot scanner picked up on a vulnerability (Critical level) from the nltk dependency. It's been fixed in 3.9.3 (draft PR here #922).