THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3hhw-38pf-pxj6 (medium) — NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely

[GHSA] GHSA-3hhw-38pf-pxj6 (medium) — NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely

medgithub_advisoriesPublished 2026-09-08

GHSA-3hhw-38pf-pxj6 Severity: medium CVE: CVE-2026-62383

NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely

## Summary

`IPIPANCorpusReader` (`nltk/corpus/reader/ipipan.py`) exposes public methods, `channels()`, `domains()`, `categories()`, and `fileids(channels=...)`, that accept a caller supplied `fileids` list and read a file via a completely unprote

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3hhw-38pf-pxj6