Medium severity5.9NVD Advisory· Published Aug 22, 2026· Updated Aug 31, 2026
CVE-2026-62385
CVE-2026-62385
Description
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, and header methods with crafted parameters to read arbitrary XML files accessible to the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nltkPyPI | < 3.10.0 | 3.10.0 |
Affected products
2Patches
Vulnerability mechanics
References
10- github.com/nltk/nltk/security/advisories/GHSA-568f-pv23-39p4nvdExploitVendor AdvisoryMitigationWEB
- github.com/advisories/GHSA-568f-pv23-39p4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-62385ghsaADVISORY
- www.vulncheck.com/advisories/nltk-path-traversal-via-framenet-and-nkjp-readersnvdThird Party AdvisoryWEB
- github.com/nltk/nltk/commit/7d1389d0789c1eca56bd0ed444089e0a3972e3edghsaWEB
- github.com/nltk/nltk/commit/bf3bf32786791394a1008258b4917a7f2d4dbcdaghsaWEB
- github.com/nltk/nltk/pull/3579ghsaWEB
- github.com/nltk/nltk/pull/3581ghsaWEB
- github.com/nltk/nltk/releases/tag/v3.10.0ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3728.yamlghsaWEB
News mentions
1- NLTK: Thirteen Path Traversal, RCE, and DoS Vulnerabilities Disclosed TogetherVypr Intelligence · Aug 22, 2026