NLTK 3.10.3 及更早版本中的模型工件(model-artifact)API 存在路径遍历漏洞。该漏洞通过调用方可控路径上的原始文件操作,绕过了 的安全检查。当 启用时,攻击者可通过 、 、 以及 maxent 参数相关 API,在允许的沙箱根目录之外读取或写入文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81722 | 7.5 HIGH | nltk PorterStemmer before 3.10.3 Quadratic-time DoS |
| CVE-2026-81727 | 7.1 HIGH | NLTK before 3.10.3 Hardlink File Overwrite via downloader |
| CVE-2026-81724 | 5.3 MEDIUM | NLTK before 3.10.3 Denial of Service via Uncontrolled Recursion |
| CVE-2026-81723 | 3.7 LOW | NLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusView |
| CVE-2026-81725 | 3.7 LOW | NLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReader |
No comments yet