PT-2026-81357 · Pypi · Nltk
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
NLTK versions prior to 3.10.3
Description
Corpus readers reopen root-derived paths using the built-in
open() function instead of nltk.pathsec.open(), which allows symbolic links to escape trusted roots. This path traversal issue enables attackers who place symlinked corpus files within a trusted data root to disclose content located outside that root through corpus reader methods such as channels(), domains(), and synonyms(). Path traversal is a flaw that allows an attacker to access files and directories that are stored outside the web root folder.Recommendations
Update NLTK to version 3.10.3 or later.
Exploit
Fix
Link Following
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nltk