
🚨 HIGH - NLTK percent-encoded path traversal in resource loader (CVE-2026-12243) NLTK’s data resource loading path handling is vulnerable when using http://nltk.data.load() or http://nltk.data.find(), allowing crafted resource names to escape intended directories. The issue is a path traversal flaw caused by improper input validation and an incomplete fix: a regex blocks literal ../ but fails to catch percent-encoded sequences like ..%2f, and url2pathname() decodes after validation. An attacker exploits this by supplying a malicious resource identifier to any app path that accepts user-controlled NLTK resource names (common in NLP web apps, notebooks, and CLI tooling), with exposure amplified when pathsec.ENFORCE=False. Successful exploitation enables arbitrary file read of any file accessible to the Python process, risking secrets disclosure, credential leakage, and downstream compromise. 👉 Affected: nltk 3.9.4 | Upgrade to No fix yet — treat as suspicious
Post summary
The article announces a high‑severity percent‑encoded path traversal flaw in NLTK’s resource loader, outlining its mechanics and potential impact, but does not provide a PoC, exploit code, active exploitation report, or any patch or workaround.
