Vulnerability Description
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nltk | Nltk | < 3.10.3 |
Related Weaknesses (CWE)
References
- https://github.com/nltk/nltk/security/advisories/GHSA-8mgp-746c-j5xpExploitVendor Advisory
- https://www.vulncheck.com/advisories/nltk-through-3.10.3-path-traversal-via-modeThird Party Advisory
- https://github.com/nltk/nltk/security/advisories/GHSA-8mgp-746c-j5xpExploitVendor Advisory
FAQ
What is CVE-2026-81726?
CVE-2026-81726 is a vulnerability with a CVSS score of 7.0 (HIGH). NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write ...
How severe is CVE-2026-81726?
CVE-2026-81726 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-81726?
Check the references section above for vendor advisories and patch information. Affected products include: Nltk Nltk.