THREAT OPS › Threat News › [NVD] CVE-2026-62383 (MEDIUM 5.5) — nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calli
[NVD] CVE-2026-62383 (MEDIUM 5.5) — nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calli
CVE-2026-62383 CVSS: 5.5 MEDIUM Published: 2026-08-22T15:16:17.883
nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids()
Indicators of compromise
- CVE-2026-62383cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-62383