Path Traversal Vulnerability in NLTK Product by NLTK
CVE-2026-62385
8.2HIGH
What is CVE-2026-62385?
NLTK versions prior to 3.10.0 have a vulnerability in the FramenetCorpusReader and NKJPCorpusReader components that results in path traversal. This flaw allows malicious users to manipulate the XML parsing process using unsafe selectors or crafted index states, enabling them to access and read arbitrary XML files located outside the designated corpus root. Attackers can exploit methods such as frame_by_name, doc, lu, and header by supplying specially crafted parameters, raising significant security concerns regarding unauthorized file access.
Affected Version(s)
nltk 0 < 3.10.0
nltk 3.10.0
