← Zurück zur CVE-Suche

CVE-2026-62388

nltk

Beschreibung

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

CVSS 7.5EPSS 0.457%Risiko 0.78
Quelle öffnen
Veröffentlicht
2026-08-22 15:16:18
Betroffene Versionen
<3.10.0
Typ
Bibliothek
Zuletzt geändert
2026-08-27 19:54:52
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N