THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6hm5-jgcp-p838 (high) — Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

[GHSA] GHSA-6hm5-jgcp-p838 (high) — Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

medgithub_advisoriesPublished 2026-07-31

GHSA-6hm5-jgcp-p838 Severity: high CVE: CVE-2026-12072

Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)

### Summary A path-traversal vulnerability in `NKJPCorpusReader` allows an attacker who can influence the `fileids` argument of its public read methods (`header`, `raw`, `words`, `sent

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6hm5-jgcp-p838