Medium severity6.5NVD Advisory· Published Aug 22, 2026· Updated Aug 31, 2026
CVE-2026-65915
CVE-2026-65915
Description
NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nltkPyPI | < 3.10.0 | 3.10.0 |
Affected products
1Patches
Vulnerability mechanics
References
8- github.com/nltk/nltk/security/advisories/GHSA-72r2-7mfr-5xr9nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-72r2-7mfr-5xr9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-65915ghsaADVISORY
- www.vulncheck.com/advisories/nltk-before-arbitrary-file-read-via-filesystempathpointernvdThird Party AdvisoryWEB
- github.com/nltk/nltk/commit/69db9911fdba914ceeaca7aec6e892d1b14586a9ghsaWEB
- github.com/nltk/nltk/pull/3522ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3731.yamlghsaWEB
- huntr.com/bounties/a510de7b-ffaf-4a83-9bf8-fa7e63f4bd2dghsaWEB
News mentions
1- NLTK: Thirteen Path Traversal, RCE, and DoS Vulnerabilities Disclosed TogetherVypr Intelligence · Aug 22, 2026