PT-2026-81355 · Pypi · Nltk
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
NLTK versions prior to 3.10.3
Description
A path sandbox bypass exists in corpus-reader constructors, enabling attackers to read files outside the intended data root. By supplying arbitrary corpus root paths to the
LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors, attackers can access filesystem content and SQLite databases beyond the pathsec sandbox boundary.Recommendations
Update to version 3.10.3 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nltk