Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-81726

Опубликовано: 27 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7

Описание

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.

РелизСтатусПримечание
devel

needs-triage

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

esm-infra-legacy/trusty

needs-triage

jammy

needs-triage

noble

needs-triage

Показывать по

EPSS

Процентиль: 18%
0.0026
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 8.7
redhat
20 дней назад

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.

CVSS3: 7
nvd
20 дней назад

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.

CVSS3: 7
debian
20 дней назад

NLTK through 3.10.3 contains a path traversal vulnerability in model-a ...

CVSS3: 7
github
14 дней назад

NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots

CVSS3: 7
fstec
около 1 месяца назад

Уязвимость прикладного программного интерфейса пакета библиотек для символьной и статистической обработки естественного языка NLTK, позволяющая нарушителю обойти существующие механизмы безопасности и получить доступ на чтение и запись произвольных файлов

EPSS

Процентиль: 18%
0.0026
Низкий

7 High

CVSS3