PT-2026-79558 · Pypi · Nltk
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
NLTK versions prior to 3.10.2
Description
A symlink-based sandbox bypass exists in the FramenetCorpusReader. This issue allows attackers to read arbitrary XML files located outside the corpus root. By placing symlinks with names that contain no path separators inside the corpus subdirectory, attackers can bypass the path validation guard. These symlinks are then resolved to files outside the intended directory when accessed through the
frame by name(), lu file(), or doc() methods.Recommendations
Update NLTK to version 3.10.2 or later.
Exploit
Fix
Link Following
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nltk