PT-2026-24105 · Nltk · Nltk

Published

2026-03-09

·

Updated

2026-05-25

·

CVE-2026-0846

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions nltk version 3.9.2
Description A flaw exists in the filestring() function within the nltk.util module. This issue allows for arbitrary file reading because of inadequate validation of input paths. The function directly opens files specified by user-provided input without proper sanitization, potentially allowing attackers to access sensitive system files by supplying absolute paths or using path traversal techniques. This can be exploited both locally and remotely, especially in applications where the function is used within web APIs or other interfaces that accept user input. The vulnerable function is filestring().
Recommendations Versions prior to 3.9.2 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2026-0846
GHSA-H8WQ-7XC4-P3QX
PYSEC-2026-97
USN-8302-1

Affected Products

Nltk