THREAT OPS › Threat News › [GHSA] GHSA-8mgp-746c-j5xp (high) — NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
[GHSA] GHSA-8mgp-746c-j5xp (high) — NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
GHSA-8mgp-746c-j5xp Severity: high CVE: CVE-2026-81726
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
### Summary
Several model-artifact APIs still treat caller-controlled model paths as ordinary filenames even when NLTK path security is enforced. The same outside-root paths are rejected by guarded helpers, but these public read and write flows still use raw file
Indicators of compromise
- CVE-2026-81726cve
Original source: https://github.com/advisories/GHSA-8mgp-746c-j5xp