PT-2026-24105 · Nltk+2 · Nltk+2

CVE-2026-0846

·

Published

2025-12-09

·

Updated

2026-05-25

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:P
Name of the Vulnerable Software and Affected Versions nltk version 3.9.2
Description A flaw exists in the filestring() function within the nltk.util module. This issue allows for arbitrary file reading because of inadequate validation of input paths. The function directly opens files specified by user-provided input without proper sanitization, potentially allowing attackers to access sensitive system files by supplying absolute paths or using path traversal techniques. This can be exploited both locally and remotely, especially in applications where the function is used within web APIs or other interfaces that accept user input. The vulnerable function is filestring().
Recommendations Versions prior to 3.9.2 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07978
CVE-2026-0846
ECHO-DEC7-E670-9A1B
GHSA-H8WQ-7XC4-P3QX
PYSEC-2026-97
USN-8302-1

Affected Products

Linuxmint
Ubuntu
Nltk