Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-63312

Опубликовано: 22 авг. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*
Версия до 3.10.0 (исключая)

EPSS

Процентиль: 40%
0.00488
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
13 дней назад

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

CVSS3: 7.5
redhat
13 дней назад

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.

CVSS3: 7.5
debian
13 дней назад

NLTK before 3.10.0 contains an arbitrary local file read vulnerability ...

EPSS

Процентиль: 40%
0.00488
Низкий

7.5 High

CVSS3

Дефекты

CWE-22