Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-79676

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data root can disclose outside-root content through normal corpus reader methods like channels(), domains(), and synonyms().

A flaw was found in NLTK. This path traversal vulnerability allows attackers to bypass security measures by using symbolic links within trusted data roots. By staging specially crafted symlinked corpus files, an attacker can disclose sensitive information from outside the intended data directories. This could lead to unauthorized access to confidential data.

Отчет

A path traversal vulnerability exists in NLTK corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(). When processing corpus operations like channels(), domains(), or synonyms(), the application fails to enforce path restrictions on symbolic links within data roots. An attacker capable of staging crafted symlinks in a trusted corpus directory can bypass path controls to disclose arbitrary readable files outside the corpus root. File access remains bounded by local OS discretionary access controls and host container security parameters.

Меры по смягчению последствий

Restrict local write permissions on NLTK data and corpus directories to prevent unauthorized staging of symlinked files, or ensure corpus file paths are validated against trusted roots before invoking corpus reader retrieval methods.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Out of support scope
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Out of support scope
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-ogx-core-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2523560nltk: NLTK: Information disclosure via path traversal with symlink bypass

EPSS

Процентиль: 23%
0.00307
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
23 дня назад

NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data root can disclose outside-root content through normal corpus reader methods like channels(), domains(), and synonyms().

CVSS3: 5.9
nvd
23 дня назад

NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data root can disclose outside-root content through normal corpus reader methods like channels(), domains(), and synonyms().

CVSS3: 5.9
debian
23 дня назад

NLTK versions before 3.10.3 contain a path traversal vulnerability in ...

github
9 дней назад

NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement

EPSS

Процентиль: 23%
0.00307
Низкий

5.9 Medium

CVSS3