THREAT OPS › Threat News › [GHSA] GHSA-6hm5-jgcp-p838 (high) — Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
[GHSA] GHSA-6hm5-jgcp-p838 (high) — Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
GHSA-6hm5-jgcp-p838 Severity: high CVE: CVE-2026-12072
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
### Summary A path-traversal vulnerability in `NKJPCorpusReader` allows an attacker who can influence the `fileids` argument of its public read methods (`header`, `raw`, `words`, `sent
Indicators of compromise
- CVE-2026-12072cve
Original source: https://github.com/advisories/GHSA-6hm5-jgcp-p838