Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qp76-pq9f-gr9m

Опубликовано: 22 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.2
CVSS3: 5.9

Описание

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, and header methods with crafted parameters to read arbitrary XML files accessible to the application.

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, and header methods with crafted parameters to read arbitrary XML files accessible to the application.

EPSS

Процентиль: 30%
0.00367
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-73

Связанные уязвимости

CVSS3: 5.9
ubuntu
13 дней назад

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, and header methods with crafted parameters to read arbitrary XML files accessible to the application.

CVSS3: 5.9
redhat
13 дней назад

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, and header methods with crafted parameters to read arbitrary XML files accessible to the application.

CVSS3: 5.9
nvd
13 дней назад

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by supplying unsafe selectors or poisoned index state. Attackers can exploit frame_by_name, doc, lu, and header methods with crafted parameters to read arbitrary XML files accessible to the application.

CVSS3: 5.9
debian
13 дней назад

NLTK versions before 3.10.0 contain a path traversal vulnerability in ...

EPSS

Процентиль: 30%
0.00367
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-73