CVE-2026-81726

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-27 17:21

Updated : 2026-08-31 19:06


NVD link : CVE-2026-81726

Mitre link : CVE-2026-81726

CVE.ORG link : CVE-2026-81726


JSON object : View

Products Affected

nltk

  • nltk
CWE
CWE-73

External Control of File Name or Path