THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xh95-f55m-82fw (high) — Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

[GHSA] GHSA-xh95-f55m-82fw (high) — Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

highgithub_advisoriesPublished 2026-07-31

GHSA-xh95-f55m-82fw Severity: high CVE: CVE-2026-12074

Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)

### Summary `FramenetCorpusReader.frame(name)` interpolates a caller-supplied frame name into an XML file path that is read with the builtin `open()`, bypassing `CorpusReade

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xh95-f55m-82fw