THREAT OPS › Threat News › [GHSA] GHSA-p3m8-78j2-g5p3 (high) — NLTK: Default ENFORCE=False Disables All pathsec Security Controls
[GHSA] GHSA-p3m8-78j2-g5p3 (high) — NLTK: Default ENFORCE=False Disables All pathsec Security Controls
GHSA-p3m8-78j2-g5p3 Severity: high CVE: CVE-2026-62388
NLTK: Default ENFORCE=False Disables All pathsec Security Controls
NLTK's pathsec.py security module defaults to ENFORCE=False (line 24), which means all 8 security validation functions only emit RuntimeWarning instead of raising exceptions when violations are detected.
The pathsec module was introduced as the fix for CVE-2024-39705 (arbitr
Indicators of compromise
- CVE-2026-62388cve
- CVE-2024-39705cve
- CVE-2026-0846cve
- http://169.254.169.254/url
Original source: https://github.com/advisories/GHSA-p3m8-78j2-g5p3