Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-62388

Опубликовано: 22 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

A flaw was found in NLTK. The software's default settings in pathsec.py cause security checks to only issue warnings rather than actively preventing malicious actions. This allows attackers to bypass safeguards designed to prevent unauthorized access to files (path traversal) and the execution of harmful code through data processing (pickle deserialization). Consequently, attackers can exploit these disabled security controls to compromise the system.

Отчет

NLTK versions before 3.10.0 in Red Hat products are configured by default to not enforce security validations for path traversal and pickle deserialization. This insecure default allows attackers to bypass these protections, as security controls are only active when manually enabled, increasing the risk of arbitrary code execution or unauthorized file access.

Меры по смягчению последствий

To mitigate this issue, ensure that the NLTK security validation enforcement is enabled. This can be achieved by setting nltk.internals.pathsec.ENFORCE = True in your application's initialization code before processing untrusted data. This change may require restarting any services or applications that utilize NLTK.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Not affected
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Affected
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Affected
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Will not fix
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ogx-core-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1188
https://bugzilla.redhat.com/show_bug.cgi?id=2521328NLTK: NLTK: Bypass of path traversal and pickle deserialization protections due to insecure default configuration

EPSS

Процентиль: 38%
0.00457
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
13 дней назад

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

CVSS3: 7.5
nvd
13 дней назад

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

CVSS3: 7.5
debian
13 дней назад

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, ca ...

github
2 дня назад

NLTK: Default ENFORCE=False Disables All pathsec Security Controls

EPSS

Процентиль: 38%
0.00457
Низкий

7.5 High

CVSS3