Vulnerability Description
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/nltk/nltk/security/advisories/GHSA-x5ph-mj9p-rfr8
- https://www.vulncheck.com/advisories/nltk-streambackedcorpusview-bypasses-pathse
FAQ
What is CVE-2026-63312?
CVE-2026-63312 is a vulnerability with a CVSS score of 7.5 (HIGH). NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers ...
How severe is CVE-2026-63312?
CVE-2026-63312 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-63312?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.