Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary. | |
| Title | NLTK 3.10.2 Path Traversal via corpus-reader constructors | |
| First Time appeared |
Nltk
Nltk nltk |
|
| Weaknesses | CWE-73 | |
| CPEs | cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nltk
Nltk nltk |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-25T17:42:56.934Z
Reserved: 2026-08-25T11:10:13.698Z
Link: CVE-2026-79674
Updated: 2026-08-25T17:42:34.064Z
Status : Received
Published: 2026-08-25T16:17:27.873
Modified: 2026-08-25T18:18:06.437
Link: CVE-2026-79674
No data.
OpenCVE Enrichment
Updated: 2026-08-25T17:15:05Z
-
CWE-73
External Control of File Name or Path