top of page
perceptive_background_267k.jpg

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-contro…

Published:

27 augustus 2026 om 00:00:00

Alert date:

27 augustus 2026 om 20:17:27

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

NLTK versions through 3.10.3 contain a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. The vulnerability affects TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs. Attackers can exploit this flaw to read or write files outside allowed sandbox roots even when pathsec is enabled. The issue stems from the use of raw file operations on caller-controlled paths rather than properly sanitized paths. This represents a significant security risk for applications that rely on NLTK's pathsec mechanism for sandbox enforcement. The vulnerability has been assigned CVE-2026-81726 and is documented in both the NVD and GitHub Security Advisories. Organizations using NLTK for natural language processing tasks should prioritize patching or mitigating this vulnerability.

Technical details

Mitigation steps:

Affected products:

NLTK 3.10.3 and earlier

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page