Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-63312

Опубликовано: 22 авг. 2026
Источник: debian
EPSS Низкий

Описание

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nltkfixed3.10.0-1package
nltkno-dsatrixiepackage

Примечания

  • https://github.com/nltk/nltk/security/advisories/GHSA-x5ph-mj9p-rfr8

EPSS

Процентиль: 45%
0.00563
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
13 дней назад

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

CVSS3: 7.5
redhat
13 дней назад

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

CVSS3: 7.5
nvd
13 дней назад

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

EPSS

Процентиль: 45%
0.00563
Низкий