THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f833-7jw8-xwrv (high) — NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)

[GHSA] GHSA-f833-7jw8-xwrv (high) — NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)

medgithub_advisoriesPublished 2026-09-08

GHSA-f833-7jw8-xwrv Severity: high CVE: CVE-2026-62384

NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)

This is a **new, distinct vulnerability**: a bypass of the fix already published as GHSA-xh95-f55m-82fw ("Path traversal in NLTK FramenetCorpusReader.frame() allows arbitrary

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f833-7jw8-xwrv