


Perceptive Security
SOC/SIEM Consultancy

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-contro…
Published:
27 augustus 2026 om 00:00:00
Alert date:
27 augustus 2026 om 20:17:27
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
NLTK versions through 3.10.3 contain a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. The vulnerability affects TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs. Attackers can exploit this flaw to read or write files outside allowed sandbox roots even when pathsec is enabled. The issue stems from the use of raw file operations on caller-controlled paths rather than properly sanitized paths. This represents a significant security risk for applications that rely on NLTK's pathsec mechanism for sandbox enforcement. The vulnerability has been assigned CVE-2026-81726 and is documented in both the NVD and GitHub Security Advisories. Organizations using NLTK for natural language processing tasks should prioritize patching or mitigating this vulnerability.
Technical details
Mitigation steps:
Affected products:
NLTK 3.10.3 and earlier
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-81726
https://github.com/nltk/nltk/security/advisories/GHSA-8mgp-746c-j5xp
https://www.vulncheck.com/advisories/nltk-through-3.10.3-path-traversal-via-model-artifact-apis
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
