PT-2026-82621 · Pypi · Nltk

CVE-2026-81726

·

Published

2026-08-12

·

Updated

2026-09-02

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NLTK versions prior to 3.10.4
Description Path traversal occurs in model-artifact APIs when pathsec is enabled. The issue arises from the use of raw file operations on caller-controlled paths, which allows bypassing pathsec enforcement. This enables attackers to read or write files outside the designated sandbox roots through the TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs.
Recommendations Update NLTK to version 3.10.4 or later.

Exploit

Fix

Link Following

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13262
CVE-2026-81726
GHSA-8MGP-746C-J5XP
GHSA-HQJ7-PHWP-C3FP
PYSEC-2026-3740

Affected Products

Nltk