CVE-2026-79674: NLTK 3.10.2 Path Traversal via corpus-reader constructors

Published Aug 25, 2026
·
Updated

NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary.

Affected Software

3 affected components
nltk nltk<3.10.3
nltk LinThesaurusCorpusReader<3.10.3
nltk PanLexLiteCorpusReader<3.10.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 3.10.3
  2. Compensating control

    Ensure applications using NLTK corpus-reader constructors do not accept attacker-controlled values for corpus root paths (e.g., validate/whitelist paths so they cannot traverse outside the intended pathsec sandbox boundary).

Event History

Aug 25, 2026
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using NLTK versions before 3.10.3 are exposed if untrusted input can control the corpus root path passed to LinThesaurusCorpusReader or PanLexLiteCorpusReader. The issue can expose files and SQLite databases outside the intended NLTK data-root sandbox.

2

Does exploitation require authentication or user interaction?

No. The supplied vector indicates network-reachable exploitation with low complexity, no privileges required, and no user interaction, provided an attacker can supply an arbitrary corpus root path to an affected constructor.

3

What is the recommended remediation?

Upgrade NLTK to version 3.10.3 or later. If an immediate upgrade is not possible, do not allow untrusted input to determine corpus root paths for the affected constructors, and restrict those paths to an approved data root.

4

How can I determine whether an application is affected?

Check whether it uses an NLTK version earlier than 3.10.3 and instantiates LinThesaurusCorpusReader or PanLexLiteCorpusReader. It is particularly affected if corpus root paths originate from requests, configuration controlled by untrusted users, uploaded content, or other attacker-influenced sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203