CVE-2026-81726 HIGH

CVE-2026-81726: NLTK through 3.10.3 Path Traversal via Model-Artifact APIs

Vendor Nltk
Product nltk
Weakness CWE-73
Published August 27, 2026
Last update August 27, 2026

CVSS base score

8.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 27, 2026 Record updated

Related vulnerabilities

04Related CVE