CVE-2026-62383
EUVD-2026-6433922.08.2026, 15:16
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids() methods with the symlink filename.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nltk | nltk | 3.10.0 ≤ 𝑥 < 3.10.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases