Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-62385— NLTK 3.9.4 Path Traversal via FrameNet and NKJP Readers

CVSS 5.9 · Medium

Possible ATT&CK Techniques 1AI

T1555 · Credentials from Password Stores

Affected Version Matrix 2

VendorProductVersion RangeStatus
nltknltk< 3.10.0affected
3.10.0unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-62385

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
NLTK 3.9.4 Path Traversal via FrameNet and NKJP Readers
Source: CVE Program / CVE List V5
Vulnerability Description
NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, and header methods with crafted parameters to read arbitrary XML files accessible to the application.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
文件名或路径的外部可控制
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
nltknltk 0 ~ 3.10.0 -

II. Public POCs for CVE-2026-62385

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-62385

登录查看更多情报信息。

Vendor Advisories for CVE-2026-62385 (2)

Same Patch Batch · nltk · 2026-08-22 · 12 CVEs total

CVE-2026-715138.8 HIGHNLTK 3.10.0 through 3.10.2 Remote Code Execution via AllowlistUnpickler Dotted-Name Bypass
CVE-2026-623887.5 HIGHNLTK before 3.10.0 Insecure Default Configuration pathsec
CVE-2026-623847.5 HIGHNLTK FramenetCorpusReader Symlink Sandbox Bypass before 3.10.2
CVE-2026-663937.5 HIGHNLTK before 3.9.4 Denial of Service via JSONTaggedDecoder
CVE-2026-633127.5 HIGHNLTK StreamBackedCorpusView Bypasses pathsec.ENFORCE Arbitrary File Read
CVE-2026-633107.1 HIGHNLTK before 3.9.3 Missing Post-Download Integrity Verification
CVE-2026-659156.5 MEDIUMNLTK before 3.10.0 Arbitrary File Read via FileSystemPathPointer
CVE-2026-706266.2 MEDIUMNLTK before 3.9.4 Symlink Escape via CorpusReader
CVE-2026-623835.5 MEDIUMnltk IPIPANCorpusReader Symlink Arbitrary File Read
CVE-2026-633115.3 MEDIUMNLTK before 3.10.0 SSRF via DNS Resolution Failure
CVE-2026-715142.5 LOWNLTK 3.9.4 through 3.10.2 Path Traversal via CrubadanCorpusReader pathsec Bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-62385

No comments yet


Leave a comment