CVE-2026-65915
EUVD-2026-6430922.08.2026, 15:16
NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nltk | nltk | 𝑥 < 3.10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration