THREAT OPS › Threat News › [GHSA] GHSA-r6gq-whwq-mvg9 (high) — NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root
[GHSA] GHSA-r6gq-whwq-mvg9 (high) — NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root
GHSA-r6gq-whwq-mvg9 Severity: high CVE: CVE-2026-70626
NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root
### Summary `nltk.corpus.reader.api.CorpusReader.open()` can be used to read files outside the intended corpus root via a symlink placed inside that root. Although NLTK blocks absolute paths and `..` traversal, the current boundary check is only lex
Indicators of compromise
- CVE-2026-70626cve
Original source: https://github.com/advisories/GHSA-r6gq-whwq-mvg9