{"id":"CVE-2026-81726","title":"nltk: NLTK: Unauthorized file access via path traversal in model-artifact APIs (CVE-2026-81726)","summary":"A flaw was found in NLTK. This vulnerability, known as path traversal, allows an attacker to bypass security restrictions in the model-artifact APIs. By exploiting this, an attacker can perform unauthorized read or write operations on file…","severity":"high","cvss":8.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N","cvssSource":"vendor","cwe":["CWE-22","CWE-59","CWE-73"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","lightspeed_core","openshift_lightspeed","ansible_automation_platform 2","openshift_ai_rhoai"],"published":"2026-08-27","updated":"2026-09-15","sourceUpdated":"2026-09-15T13:22:25+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81726.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81726.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-81726"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2525022"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81726"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81726"},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-8mgp-746c-j5xp"},{"url":"https://www.vulncheck.com/advisories/nltk-through-3.10.3-path-traversal-via-model-artifact-apis"},{"url":"https://github.com/nltk/nltk/pull/3757"},{"url":"https://github.com/nltk/nltk/pull/3759"},{"url":"https://github.com/nltk/nltk/pull/3813"},{"url":"https://github.com/nltk/nltk/commit/2a92b71827d754ae8920261e7ed0c4bb283ab2d7"},{"url":"https://github.com/nltk/nltk/commit/a44a7af69bca87e92d9c4a701fcbbe4512e8d450"},{"url":"https://github.com/nltk/nltk/commit/cbc98458b43de5f792f0382583c16df39e5c5117"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3740.yaml"},{"url":"https://github.com/advisories/GHSA-8mgp-746c-j5xp"}],"tags":["csaf","vex","red-hat","ghsa","pip"],"epss":0.00339,"epssPercentile":0.24686,"aliases":["GHSA-8mgp-746c-j5xp"],"ecosystem":"pip","scores":{"vendor":8.7,"ghsa":7},"ingestedAt":"2026-09-02T14:45:30.305Z","slug":"CVE-2026-81726","body":"## Overview\n\nA flaw was found in NLTK. This vulnerability, known as path traversal, allows an attacker to bypass security restrictions in the model-artifact APIs. By exploiting this, an attacker can perform unauthorized read or write operations on files outside the intended secure directories. This could lead to sensitive information disclosure or system compromise.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI) · no fix planned: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Lightspeed Core, OpenShift Lightspeed, … · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81726.json)\n\n**nltk: NLTK: Unauthorized file access via path traversal in model-artifact APIs** — rated Important by Red Hat. Released 2026-08-27, updated 2026-09-15.\n\nAffected:\n\n- Exploit Intelligence\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat Ansible Automation Platform 2\n- Red Hat OpenShift AI (RHOAI)\n\nNo fix planned:\n\n- Exploit Intelligence\n- Red Hat Ansible Automation Platform 2\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- OpenShift Lightspeed\n\n## Remediation\n\nWill not fix\n\nWorkarounds / mitigations:\n\n- Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.\n\n## Package advisory (CVE-2026-81726)\n\nAffected packages:\n\n- `nltk <= 3.10.3`\n\nSource: https://github.com/advisories/GHSA-8mgp-746c-j5xp","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":202006,"id":"CVE-2026-81726","ts":1789400002180,"field":"cvss","old":"7","new":"8.7"},{"seq":200733,"id":"CVE-2026-81726","ts":1789397588124,"field":"cvss","old":"8.7","new":"7"},{"seq":199428,"id":"CVE-2026-81726","ts":1789395501934,"field":"cvss","old":"7","new":"8.7"},{"seq":198673,"id":"CVE-2026-81726","ts":1789392190529,"field":"cvss","old":"8.7","new":"7"},{"seq":197004,"id":"CVE-2026-81726","ts":1789384277274,"field":"cvss","old":"7","new":"8.7"},{"seq":196364,"id":"CVE-2026-81726","ts":1789383751690,"field":"cvss","old":"8.7","new":"7"},{"seq":195292,"id":"CVE-2026-81726","ts":1789380558932,"field":"cvss","old":"7","new":"8.7"},{"seq":194135,"id":"CVE-2026-81726","ts":1789378731280,"field":"cvss","old":"8.7","new":"7"},{"seq":192922,"id":"CVE-2026-81726","ts":1789376499817,"field":"cvss","old":"7","new":"8.7"},{"seq":191709,"id":"CVE-2026-81726","ts":1789373593175,"field":"cvss","old":"8.7","new":"7"},{"seq":190494,"id":"CVE-2026-81726","ts":1789369456538,"field":"cvss","old":"7","new":"8.7"},{"seq":189281,"id":"CVE-2026-81726","ts":1789368375735,"field":"cvss","old":"8.7","new":"7"},{"seq":188064,"id":"CVE-2026-81726","ts":1789365222642,"field":"cvss","old":"7","new":"8.7"},{"seq":186851,"id":"CVE-2026-81726","ts":1789363457164,"field":"cvss","old":"8.7","new":"7"},{"seq":185637,"id":"CVE-2026-81726","ts":1789361210105,"field":"cvss","old":"7","new":"8.7"},{"seq":184424,"id":"CVE-2026-81726","ts":1789358321234,"field":"cvss","old":"8.7","new":"7"},{"seq":182675,"id":"CVE-2026-81726","ts":1789354307941,"field":"cvss","old":"7","new":"8.7"},{"seq":181468,"id":"CVE-2026-81726","ts":1789353287430,"field":"cvss","old":"8.7","new":"7"},{"seq":180261,"id":"CVE-2026-81726","ts":1789350270385,"field":"cvss","old":"7","new":"8.7"},{"seq":179054,"id":"CVE-2026-81726","ts":1789348259349,"field":"cvss","old":"8.7","new":"7"},{"seq":177847,"id":"CVE-2026-81726","ts":1789346360688,"field":"cvss","old":"7","new":"8.7"},{"seq":176640,"id":"CVE-2026-81726","ts":1789343159572,"field":"cvss","old":"8.7","new":"7"},{"seq":174757,"id":"CVE-2026-81726","ts":1789334857660,"field":"cvss","old":"7","new":"8.7"},{"seq":173552,"id":"CVE-2026-81726","ts":1789333670497,"field":"cvss","old":"8.7","new":"7"},{"seq":172366,"id":"CVE-2026-81726","ts":1789331084703,"field":"cvss","old":"7","new":"8.7"},{"seq":171180,"id":"CVE-2026-81726","ts":1789328753097,"field":"cvss","old":"8.7","new":"7"},{"seq":169975,"id":"CVE-2026-81726","ts":1789327153511,"field":"cvss","old":"7","new":"8.7"},{"seq":168770,"id":"CVE-2026-81726","ts":1789323810061,"field":"cvss","old":"8.7","new":"7"},{"seq":167565,"id":"CVE-2026-81726","ts":1789319675118,"field":"cvss","old":"7","new":"8.7"},{"seq":166360,"id":"CVE-2026-81726","ts":1789318740872,"field":"cvss","old":"8.7","new":"7"},{"seq":165155,"id":"CVE-2026-81726","ts":1789315779330,"field":"cvss","old":"7","new":"8.7"},{"seq":163950,"id":"CVE-2026-81726","ts":1789313605469,"field":"cvss","old":"8.7","new":"7"},{"seq":162745,"id":"CVE-2026-81726","ts":1789311892031,"field":"cvss","old":"7","new":"8.7"},{"seq":161540,"id":"CVE-2026-81726","ts":1789308700815,"field":"cvss","old":"8.7","new":"7"},{"seq":159653,"id":"CVE-2026-81726","ts":1789300460312,"field":"cvss","old":"7","new":"8.7"},{"seq":156642,"id":"CVE-2026-81726","ts":1789294730719,"field":"cvss","old":"8.7","new":"7"},{"seq":155437,"id":"CVE-2026-81726","ts":1789292954448,"field":"cvss","old":"7","new":"8.7"},{"seq":154232,"id":"CVE-2026-81726","ts":1789289770722,"field":"cvss","old":"8.7","new":"7"},{"seq":153099,"id":"CVE-2026-81726","ts":1789285309897,"field":"cvss","old":"7","new":"8.7"},{"seq":152522,"id":"CVE-2026-81726","ts":1789281255323,"field":"cvss","old":"8.7","new":"7"},{"seq":151483,"id":"CVE-2026-81726","ts":1789277615145,"field":"cvss","old":"7","new":"8.7"},{"seq":150444,"id":"CVE-2026-81726","ts":1789276229860,"field":"cvss","old":"8.7","new":"7"},{"seq":149411,"id":"CVE-2026-81726","ts":1789273813520,"field":"cvss","old":"7","new":"8.7"},{"seq":148378,"id":"CVE-2026-81726","ts":1789271312129,"field":"cvss","old":"8.7","new":"7"},{"seq":146410,"id":"CVE-2026-81726","ts":1789269375582,"field":"cvss","old":"7","new":"8.7"},{"seq":145215,"id":"CVE-2026-81726","ts":1789266325255,"field":"cvss","old":"8.7","new":"7"},{"seq":144119,"id":"CVE-2026-81726","ts":1789262596337,"field":"cvss","old":"7","new":"8.7"},{"seq":143023,"id":"CVE-2026-81726","ts":1789261508912,"field":"cvss","old":"8.7","new":"7"},{"seq":141854,"id":"CVE-2026-81726","ts":1789258822130,"field":"cvss","old":"7","new":"8.7"},{"seq":140695,"id":"CVE-2026-81726","ts":1789256712965,"field":"cvss","old":"8.7","new":"7"}]}