Aller au contenu

Fiche vulnérabilité

CVE-2026-0846 : faille élevée nltk nltk (CVSS 7.5)

Description

A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
9 mars 2026
Dernière mise à jour
15 juil. 2026

Produits concernés

  • nltk nltk

Références

Rechercher une autre vulnérabilité dans la base CVE