High severity8.2NVD Advisory· Published Aug 25, 2026· Updated Aug 31, 2026
CVE-2026-79674
CVE-2026-79674
Description
NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nltkPyPI | < 3.10.3 | 3.10.3 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/nltk/nltk/security/advisories/GHSA-3gq4-3j92-5w49nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-3gq4-3j92-5w49ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-79674ghsaADVISORY
- www.vulncheck.com/advisories/nltk-path-traversal-via-corpus-reader-constructorsnvdThird Party AdvisoryWEB
- github.com/nltk/nltk/commit/bc007200d123c1a98d74c2eb230f5e06c53886b8ghsaWEB
- github.com/nltk/nltk/releases/tag/v3.10.3ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3736.yamlghsaWEB
News mentions
1- Nltk Library: 16 Vulnerabilities Including Critical RCE Disclosed in BatchVypr Intelligence · Aug 27, 2026