Symlink Escape Vulnerability in NLTK by NLTK Team
CVE-2026-70626
8.6HIGH
What is CVE-2026-70626?
The NLTK library prior to version 3.9.4 has a vulnerability in the CorpusReader.open() method that allows local attackers to exploit symlink escape conditions. This flaw arises from inadequate path validation, where the system does not properly resolve symbolic links. As a result, attackers can create symlinks within the corpus root directory, leading to unauthorized access to files stored outside designated directories, potentially exposing sensitive information.
Affected Version(s)
nltk 0 < 3.9.4
nltk 3.9.4
