CVE-2026-79676
EUVD-2026-6552625.08.2026, 16:17
NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data root can disclose outside-root content through normal corpus reader methods like channels(), domains(), and synonyms().
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nltk | nltk | 𝑥 < 3.10.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases