PT-2026-79564 · Pypi · Nltk

·

CVE-2026-65915

·

Published

2026-08-22

·

Updated

2026-09-08

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NLTK versions prior to 3.10.0
Description A logic bug exists in the FileSystemPathPointer.open() function where the sandbox validation check compares a normalized path against itself, rendering the security check ineffective. This allows attackers to use file:// URLs via the nltk.data.load() function to read arbitrary files accessible to the process user, such as configuration files and credentials.
Recommendations Update NLTK to version 3.10.0 or later. As a temporary mitigation, restrict the use of the nltk.data.load() function when handling untrusted input.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65915
GHSA-72R2-7MFR-5XR9
GHSA-79PH-W9M5-4V5M
PYSEC-2026-3731

Affected Products

Nltk