High severity7.0NVD Advisory· Published Aug 27, 2026· Updated Aug 31, 2026
CVE-2026-81726
CVE-2026-81726
Description
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nltkPyPI | <= 3.10.3 | — |
Affected products
1Patches
Vulnerability mechanics
References
11- github.com/nltk/nltk/security/advisories/GHSA-8mgp-746c-j5xpnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-8mgp-746c-j5xpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-81726ghsaADVISORY
- www.vulncheck.com/advisories/nltk-through-3.10.3-path-traversal-via-model-artifact-apisnvdThird Party AdvisoryWEB
- github.com/nltk/nltk/commit/2a92b71827d754ae8920261e7ed0c4bb283ab2d7ghsaWEB
- github.com/nltk/nltk/commit/a44a7af69bca87e92d9c4a701fcbbe4512e8d450ghsaWEB
- github.com/nltk/nltk/commit/cbc98458b43de5f792f0382583c16df39e5c5117ghsaWEB
- github.com/nltk/nltk/pull/3757ghsaWEB
- github.com/nltk/nltk/pull/3759ghsaWEB
- github.com/nltk/nltk/pull/3813ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3740.yamlghsaWEB
News mentions
1- Nltk Library: 16 Vulnerabilities Including Critical RCE Disclosed in BatchVypr Intelligence · Aug 27, 2026