Path Traversal Vulnerability in NLTK Product by NLTK
CVE-2026-62385

8.2HIGH

Key Information:

Vendor

Nltk

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-62385?

NLTK versions prior to 3.10.0 have a vulnerability in the FramenetCorpusReader and NKJPCorpusReader components that results in path traversal. This flaw allows malicious users to manipulate the XML parsing process using unsafe selectors or crafted index states, enabling them to access and read arbitrary XML files located outside the designated corpus root. Attackers can exploit methods such as frame_by_name, doc, lu, and header by supplying specially crafted parameters, raising significant security concerns regarding unauthorized file access.

Affected Version(s)

nltk 0 < 3.10.0

nltk 3.10.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.