Symlink Escape Vulnerability in NLTK by NLTK Team
CVE-2026-70626

8.6HIGH

Key Information:

Vendor

Nltk

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-70626?

The NLTK library prior to version 3.9.4 has a vulnerability in the CorpusReader.open() method that allows local attackers to exploit symlink escape conditions. This flaw arises from inadequate path validation, where the system does not properly resolve symbolic links. As a result, attackers can create symlinks within the corpus root directory, leading to unauthorized access to files stored outside designated directories, potentially exposing sensitive information.

Affected Version(s)

nltk 0 < 3.9.4

nltk 3.9.4

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

leduckhuong
.