NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292). This is a new, distinct vulnerability: a bypass of the fix already published as GHSA-xh95-f55m-82fw ("Path traversal in NLTK FramenetCorpusReader.frame() allows arbitrary XML file read, bypassing the nltk.pathsec sandbox"), not a duplicate of it.
- Severity
- HighCVSS 3.1 · 7.5
- Fix
- Fixed in 3.10.2Fix recorded 3 days ago
- Affected versions
- 3.10.0 to before 3.10.2
- Weakness
- CWE-22Path Traversal
- Exploit likelihood
- 0.56% in 30 daysEPSS, higher than 45% of known flaws
- Affects
- NLTK
What to do
Update to 3.10.2 or later.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact None No data tampering
- Availability impact None No availability impact
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Open in FIRST.org calculatorReferences
- github.com · v3.10.2 (tag) patch release notes
- github.com · GHSA-f833-7jw8-xwrv vendor advisory
- nvd.nist.gov · CVE-2026-62384 vdb entry
- euvd.enisa.europa.eu · EUVD-2026-64338 vdb entry
- github.com · PR #3726 GitHub Advisory
- github.com · commit 736d321 GitHub Advisory
- github.com · PYSEC-2026-3789.yaml (main) GitHub Advisory
- vulncheck.com · nltk-framenetcorpusreader-symlink-sandbox-bypass-before GitHub Advisory