MEDIUM 6.8 NVD
CVE-2026-62383
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids() methods with the symlink filename.
References
- https://github.com/nltk/nltk/security/advisories/GHSA-3hhw-38pf-pxj6
- https://www.vulncheck.com/advisories/nltk-ipipancorpusreader-symlink-arbitrary-file-read
This medium severity vulnerability with a CVSS score of 6.8 was published on 2026-08-22 via NVD.
vulnfeed aggregates 11022 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.