Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-62384

Опубликовано: 22 авг. 2026
Источник: debian
EPSS Низкий

Описание

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nltkfixed3.10.3-1package
nltkno-dsatrixiepackage

Примечания

  • https://github.com/nltk/nltk/security/advisories/GHSA-f833-7jw8-xwrv

  • CVE exists because it is possible to bypass the fix for CVE-2026-12074

EPSS

Процентиль: 40%
0.00488
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
13 дней назад

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.

CVSS3: 7.5
redhat
13 дней назад

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.

CVSS3: 7.5
nvd
13 дней назад

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.

EPSS

Процентиль: 40%
0.00488
Низкий