THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-62383 (MEDIUM 5.5) — nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calli

[NVD] CVE-2026-62383 (MEDIUM 5.5) — nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calli

mednvdPublished 2026-08-22

CVE-2026-62383 CVSS: 5.5 MEDIUM Published: 2026-08-22T15:16:17.883

nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in the corpus root directory and read arbitrary files accessible to the process by calling channels(), domains(), categories(), or fileids()

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-62383