VYPR

Nltk

by Nltk

pypi: nltk

Source repositories

CVEs (52)

  • CVE-2026-63312HigAug 22, 2026
    risk 0.42cvss 7.5epss 0.01

    NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of…

  • CVE-2026-62388HigAug 22, 2026
    risk 0.42cvss 7.5epss 0.01

    NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls…

  • CVE-2026-62384HigAug 22, 2026
    risk 0.42cvss 7.5epss 0.01

    NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass…

  • CVE-2026-72818HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.01

    The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label…

  • CVE-2026-54293HigJun 22, 2026
    risk 0.42cvss 7.5epss 0.01

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path traversal via URL-encoded path separators…

  • CVE-2026-12199HigJun 17, 2026
    risk 0.42cvss 7.5epss 0.00

    A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when started in its default mode. The server listens on all interfaces and processes a specific unauthenticated GET request…

  • CVE-2026-33231HigMar 20, 2026
    risk 0.42cvss 7.5epss 0.01

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauthenticated remote shutdown of the local WordNet…

  • CVE-2026-0846HigMar 9, 2026
    risk 0.42cvss 7.5epss 0.01

    A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access…

  • CVE-2026-0847HigMar 4, 2026
    risk 0.42cvss 7.5epss 0.01

    A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fail to properly sanitize or validate file…

  • CVE-2021-3842HigJan 4, 2022
    risk 0.42cvss 7.5epss 0.01

    nltk is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-43854HigDec 23, 2021
    risk 0.42cvss 7.5epss 0.03

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Versions prior to 3.6.5 are vulnerable to regular expression denial of service (ReDoS) attacks. The…

  • CVE-2021-3828HigSep 27, 2021
    risk 0.42cvss 7.5epss 0.02

    nltk is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2019-14751HigAug 22, 2019
    risk 0.42cvss 7.5epss 0.06

    NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction.

  • CVE-2026-81727HigAug 27, 2026
    risk 0.39cvss 7.1epss 0.00

    NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a…

  • CVE-2026-81726HigAug 27, 2026
    risk 0.39cvss 7.0epss 0.00

    NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser,…

  • CVE-2026-12072higJul 31, 2026
    risk 0.38cvss —epss —

    ### Summary A path-traversal vulnerability in `NKJPCorpusReader` allows an attacker who can influence the `fileids` argument of its public read methods (`header`, `raw`, `words`, `sents`, `tagged_words`) to read files outside the corpus root. The reader builds the…

  • CVE-2026-65915MedAug 22, 2026
    risk 0.35cvss 6.5epss 0.00

    NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files…

  • CVE-2026-12261MedAug 7, 2026
    risk 0.35cvss 6.5epss 0.00

    A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of package-isolated roots, and validates package…

  • CVE-2026-70626MedAug 22, 2026
    risk 0.33cvss 6.2epss 0.00

    NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability exists because path validation is lexical and does not account for symlink resolution, enabling…

  • CVE-2026-33230MedMar 20, 2026
    risk 0.33cvss 6.1epss 0.00

    NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` contains a reflected cross-site scripting issue in the…