High severity7.0NVD Advisory· Published Aug 27, 2026
CVE-2026-81726
CVE-2026-81726
Description
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.