CVE-2026-62384Patch(nltk / nltk)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nltk nltk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can place symlinks with names containing no path separators inside the corpus subdirectory, which pass the path validation guard and are resolved to files outside the intended corpus root when accessed via frame_by_name(), _lu_file(), or doc() methods.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nltk

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-23); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
nltk

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-23: 2Mentions · 2026-09-08: 1Patch / Workaround · 2026-08-23: 2Technical Details · 2026-08-23: 2Technical Details · 2026-09-08: 108-2309-08
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-232
Patch2
2026-09-081
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 NLTK (Natural Language Toolkit), Symlink-Based Sandbox Bypass, #CVE-2026-62384 (High) -DC-Sep2026-2226 https://dailycve.com/nltk-natural-language-toolkit-symlink-based-sandbox-bypass-cve-2026-62384-high-dc-sep2026-2226/

    Post summary

    The text announces CVE‑2026‑62384 as a high‑severity, symlink‑based sandbox bypass in NLTK, but does not provide PoC, exploit, or patch information.

    0000033
    236 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-62384 - Symlink sandbox bypass in NLTK leads to arbitrary file read. CVSS 7.5. Update to version 3.10.2 now. #CVE #Python #infosec https://www.valtersit.com/cve/CVE-2026-62384 #CVE #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #iceland #israel

    Post summary

    The tweet announces a CVE‑2026‑62384 vulnerability in NLTK, provides technical details and a CVSS score, and recommends updating to version 3.10.2 to remediate the issue.

    0000046
    1.0K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-62384 - Symlink sandbox bypass in NLTK FramenetCorpusReader. Arbitrary XML file read. CVSS 7.5. Update to 3.10.2 now. https://www.valtersit.com/cve/CVE-2026-62384/ #NLTK #CVE #CVEAlert #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #iceland #israel

    Post summary

    CVE-2026-62384 is a symlink sandbox bypass in NLTK’s FramenetCorpusReader that allows arbitrary XML file reads with a CVSS score of 7.5, and it has been mitigated by updating to version 3.10.2.

    0000036
    1.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnltknltk---

Explore more