Skip to content
archivevulnerability · 08 Sep 2026 · 16:55 UTC

GHSA-p4rw-rvv2-7xwr: NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

VULNCVE-2026-79676source · GTH
HIGHHigh-risk vulnerability

last 60 dispatches · spectrum

### Summary Several corpus readers still step outside NLTK's symlink-aware trusted-root model. They derive in-root paths from trusted corpus state, convert those paths back into plain strings, and reopen them with built-in `open()` rather than `nltk.pathsec.open()`. ### Details - **Vulnerability type:** Path traversal and symlink boundary bypass - **Affected component:** `nltk.corpus.reader.ipipan`, `nltk.corpus.reader.crubadan`, `nltk.corpus.reader.lin` - **Affected versions:** Published `3.9.4` and current source `v3.10.0-rc2` both reproduced. …

CVE · detail
grounded ✓primary source ↗

loading threat intel…

Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected