Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-62388

Опубликовано: 22 авг. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*
Версия до 3.10.0 (исключая)

EPSS

Процентиль: 38%
0.00457
Низкий

7.5 High

CVSS3

Дефекты

CWE-1188

Связанные уязвимости

CVSS3: 7.5
ubuntu
13 дней назад

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

CVSS3: 7.5
redhat
13 дней назад

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

CVSS3: 7.5
debian
13 дней назад

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, ca ...

github
2 дня назад

NLTK: Default ENFORCE=False Disables All pathsec Security Controls

EPSS

Процентиль: 38%
0.00457
Низкий

7.5 High

CVSS3

Дефекты

CWE-1188