THREAT OPS › Threat News › [GHSA] GHSA-p4rw-rvv2-7xwr (high) — NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
[GHSA] GHSA-p4rw-rvv2-7xwr (high) — NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
GHSA-p4rw-rvv2-7xwr Severity: high CVE: CVE-2026-79676
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
### Summary
Several corpus readers still step outside NLTK's symlink-aware trusted-root model. They derive in-root paths from trusted corpus state, convert those paths back into plain strings, and reopen them with built-in `open()` rather than `nltk.paths
Indicators of compromise
- CVE-2026-79676cve
Original source: https://github.com/advisories/GHSA-p4rw-rvv2-7xwr