THREAT OPS › Threat News › [GHSA] GHSA-x5ph-mj9p-rfr8 (high) — NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read
[GHSA] GHSA-x5ph-mj9p-rfr8 (high) — NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read
GHSA-x5ph-mj9p-rfr8 Severity: high CVE: CVE-2026-63312
NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read
## Summary Setting `nltk.pathsec.ENFORCE = True` is documented to sandbox all file access to allowed NLTK data directories and raise `PermissionError` on unauthorized access. However, `StreamBackedCorpusView` opens files via `builtins.open()` directly, bypassin
Indicators of compromise
- CVE-2026-63312cve
Original source: https://github.com/advisories/GHSA-x5ph-mj9p-rfr8