Medium severity5.5NVD Advisory· Published Aug 22, 2026· Updated Aug 27, 2026
CVE-2026-62383
CVE-2026-62383
Description
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids() methods with the symlink filename.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nltkPyPI | >= 3.10.0, < 3.10.2 | 3.10.2 |
Affected products
2Patches
Vulnerability mechanics
References
8- github.com/nltk/nltk/security/advisories/GHSA-3hhw-38pf-pxj6nvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-3hhw-38pf-pxj6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-62383ghsaADVISORY
- www.vulncheck.com/advisories/nltk-ipipancorpusreader-symlink-arbitrary-file-readnvdThird Party AdvisoryWEB
- github.com/nltk/nltk/commit/ee1a42e51982c4dce6ad3ee77ff1ac43894288abghsaWEB
- github.com/nltk/nltk/pull/3727ghsaWEB
- github.com/nltk/nltk/releases/tag/v3.10.2ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3726.yamlghsaWEB
News mentions
1- NLTK: Thirteen Path Traversal, RCE, and DoS Vulnerabilities Disclosed TogetherVypr Intelligence · Aug 22, 2026