HIGH 8.7 NVD
CVE-2026-62388
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. At
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.
References
- https://github.com/nltk/nltk/security/advisories/GHSA-p3m8-78j2-g5p3
- https://www.vulncheck.com/advisories/nltk-before-insecure-default-configuration-pathsec
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-22 via NVD.
vulnfeed aggregates 11022 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.