Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-65915

Опубликовано: 22 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.

A flaw was found in NLTK. A logic bug in the FileSystemPathPointer.open() function allows the sandbox validation check to be bypassed. A remote attacker can exploit this by providing specially crafted file:// Uniform Resource Locators (URLs) to nltk.data.load(). This enables the attacker to read arbitrary files on the system, potentially leading to the disclosure of sensitive information such as credentials and configuration files.

Отчет

This vulnerability in NLTK allows an authenticated attacker to read arbitrary files accessible to the process by supplying specially crafted file:// URLs to nltk.data.load(). This could lead to information disclosure, including sensitive credentials or configuration data, within affected Red Hat products such as Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform, and Red Hat OpenShift AI. Exploitation requires the application to process untrusted input that can be interpreted as a file:// URL by NLTK.

Меры по смягчению последствий

Mitigation for this issue involves ensuring that applications utilizing the NLTK library do not process untrusted file:// URLs through nltk.data.load(). Implement input validation and sanitization for any data passed to NLTK functions that could resolve file paths. Additionally, running applications that use NLTK with the principle of least privilege can limit the impact of successful exploitation by restricting access to sensitive files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-ogx-core-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2521343nltk: NLTK: Arbitrary file read due to logic bug in FileSystemPathPointer

EPSS

Процентиль: 21%
0.00286
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
8 дней назад

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.

CVSS3: 6.5
nvd
10 дней назад

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.

CVSS3: 6.5
debian
10 дней назад

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPoint ...

CVSS3: 6.5
github
10 дней назад

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.

EPSS

Процентиль: 21%
0.00286
Низкий

6.5 Medium

CVSS3