THREAT OPS › Threat News › [GHSA] GHSA-568f-pv23-39p4 (high) — NLTK: Stable FrameNet and NKJP readers parse outside-root XML
[GHSA] GHSA-568f-pv23-39p4 (high) — NLTK: Stable FrameNet and NKJP readers parse outside-root XML
GHSA-568f-pv23-39p4 Severity: high CVE: CVE-2026-62385
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
### Summary
Published `nltk==3.9.4` still contains several XML-reader entrypoints that build parser paths from caller-controlled selectors or trusted-looking index state without preserving the corpus-root boundary.
### Details
- **Vulnerability type:** Path traversal and truste
Indicators of compromise
- CVE-2026-62385cve
Original source: https://github.com/advisories/GHSA-568f-pv23-39p4