PT-2026-79569 · Pypi · Nltk

·

CVE-2026-70626

·

Published

2026-08-22

·

Updated

2026-09-08

CVSS v4.0

8.6

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NLTK versions prior to 3.9.4
Description A symlink escape issue exists in the CorpusReader.open() function. This occurs because path validation is performed lexically and fails to account for symlink resolution. Consequently, a local attacker can place symlinks within the corpus root to read arbitrary files located outside the intended boundary.
Recommendations Update to version 3.9.4 or later.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70626
GHSA-8H9M-22MV-QV5R
GHSA-R6GQ-WHWQ-MVG9
PYSEC-2026-3732

Affected Products

Nltk