CVE-2026-62388
NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.46%
- CWE
- CWE-1188
- Published
- 2026-08-22
- Last modified
- 2026-08-29
Affected products
- nltk nltk
- nltk nltk
Weakness type
Related vulnerabilities
- CVE-2026-87827 — KGUARD DVR unauthenticated remote command execution vulnerability
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been...
- CVE-2026-77348 — Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`
- CVE-2026-53507 — oasdiff actions resolve external $refs by default, enabling SSRF and disclosure of structured files on pull-request runs
- CVE-2026-75062 — Eval Injection in google/langfun via default lf.query protocol
- CVE-2026-55581 — mcp-shell: Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
- CVE-2026-77915 — rConfig Core 8.0.0 < 8.2.10 Unauthorized Admin Registration via web.php
- CVE-2026-75926 — Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant