Medium severity5.5NVD Advisory· Published Aug 22, 2026
CVE-2026-62383
CVE-2026-62383
Description
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids() methods with the symlink filename.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.