Medium severity6.2NVD Advisory· Published Aug 22, 2026· Updated Aug 31, 2026
CVE-2026-70626
CVE-2026-70626
Description
NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for symlink resolution, enabling attackers to place symlinks inside the corpus root to access files outside the intended boundary.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nltkPyPI | < 3.9.4 | 3.9.4 |
Affected products
1Patches
Vulnerability mechanics
References
8- github.com/nltk/nltk/security/advisories/GHSA-r6gq-whwq-mvg9nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-r6gq-whwq-mvg9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-70626ghsaADVISORY
- www.vulncheck.com/advisories/nltk-before-symlink-escape-via-corpusreadernvdVendor AdvisoryWEB
- github.com/nltk/nltk/commit/1b0e519e2324bc1a273d56edee63e44d0ad85b48ghsaWEB
- github.com/nltk/nltk/pull/3522ghsaWEB
- github.com/nltk/nltk/releases/tag/3.9.4ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3732.yamlghsaWEB
News mentions
1- NLTK: Thirteen Path Traversal, RCE, and DoS Vulnerabilities Disclosed TogetherVypr Intelligence · Aug 22, 2026