NLTK 3.10.3 之前的版本中存在路径沙箱绕过漏洞,该漏洞位于语料库阅读器(corpus-reader)的构造函数中,允许攻击者读取位于预期数据根目录之外的文件。攻击者可以通过向 LinThesaurusCorpusReader 和 PanLexLiteCorpusReader 的构造函数提供任意的语料库根路径,来访问路径沙箱边界之外的文件系统内容和 SQLite 数据库。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-79657 | 9.8 CRITICAL | NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle Deserialization |
| CVE-2026-79675 | 9.8 CRITICAL | NLTK before 3.10.3 JVM Argument Injection via Per-Call Options |
| CVE-2026-78683 | 9.6 CRITICAL | NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization |
| CVE-2026-78680 | 7.8 HIGH | NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary |
| CVE-2026-78681 | 7.5 HIGH | NLTK before 3.10.3 Entity Expansion DoS via ElementTree |
| CVE-2026-78682 | 7.5 HIGH | NLTK before 3.10.3 SSRF Protection Bypass via Proxy |
| CVE-2026-79676 | 5.9 MEDIUM | NLTK before 3.10.3 Path Traversal via Symlink Bypass |
No comments yet