Bug 2521349 (CVE-2026-62384) - CVE-2026-62384 nltk: NLTK: Information Disclosure via Symlink Sandbox Bypass
Summary: CVE-2026-62384 nltk: NLTK: Information Disclosure via Symlink Sandbox Bypass
Keywords:
Status: NEW
Alias: CVE-2026-62384
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2524983 2524984
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-22 14:32 UTC by OSIDB Bzimport
Modified: 2026-08-27 14:24 UTC (History)
19 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-22 14:32:37 UTC
NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.


Note You need to log in before you can comment on or make changes to this bug.