---
id: CVE-2026-81726
title: >-
  nltk: NLTK: Unauthorized file access via path traversal in model-artifact APIs
  (CVE-2026-81726)
summary: >-
  A flaw was found in NLTK. This vulnerability, known as path traversal, allows
  an attacker to bypass security restrictions in the model-artifact APIs. By
  exploiting this, an attacker can perform unauthorized read or write operations
  on file…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'
cvssSource: vendor
cwe:
  - CWE-22
  - CWE-59
  - CWE-73
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - exploit_intelligence
  - lightspeed_core
  - openshift_lightspeed
  - ansible_automation_platform 2
  - openshift_ai_rhoai
published: '2026-08-27'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T13:22:25+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81726.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81726.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-81726'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2525022'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-81726'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81726'
  - url: 'https://github.com/nltk/nltk/security/advisories/GHSA-8mgp-746c-j5xp'
  - url: >-
      https://www.vulncheck.com/advisories/nltk-through-3.10.3-path-traversal-via-model-artifact-apis
  - url: 'https://github.com/nltk/nltk/pull/3757'
  - url: 'https://github.com/nltk/nltk/pull/3759'
  - url: 'https://github.com/nltk/nltk/pull/3813'
  - url: >-
      https://github.com/nltk/nltk/commit/2a92b71827d754ae8920261e7ed0c4bb283ab2d7
  - url: >-
      https://github.com/nltk/nltk/commit/a44a7af69bca87e92d9c4a701fcbbe4512e8d450
  - url: >-
      https://github.com/nltk/nltk/commit/cbc98458b43de5f792f0382583c16df39e5c5117
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3740.yaml
  - url: 'https://github.com/advisories/GHSA-8mgp-746c-j5xp'
tags:
  - csaf
  - vex
  - red-hat
  - ghsa
  - pip
epss: 0.00339
epssPercentile: 0.24686
aliases:
  - GHSA-8mgp-746c-j5xp
ecosystem: pip
scores:
  vendor: 8.7
  ghsa: 7
ingestedAt: '2026-09-02T14:45:30.305Z'
---

## Overview

A flaw was found in NLTK. This vulnerability, known as path traversal, allows an attacker to bypass security restrictions in the model-artifact APIs. By exploiting this, an attacker can perform unauthorized read or write operations on files outside the intended secure directories. This could lead to sensitive information disclosure or system compromise.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI) · no fix planned: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Lightspeed Core, OpenShift Lightspeed, … · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81726.json)

**nltk: NLTK: Unauthorized file access via path traversal in model-artifact APIs** — rated Important by Red Hat. Released 2026-08-27, updated 2026-09-15.

Affected:

- Exploit Intelligence
- Lightspeed Core
- OpenShift Lightspeed
- Red Hat Ansible Automation Platform 2
- Red Hat OpenShift AI (RHOAI)

No fix planned:

- Exploit Intelligence
- Red Hat Ansible Automation Platform 2
- Lightspeed Core
- OpenShift Lightspeed
- Red Hat OpenShift AI (RHOAI)

Not affected:

- OpenShift Lightspeed

## Remediation

Will not fix

Workarounds / mitigations:

- Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

## Package advisory (CVE-2026-81726)

Affected packages:

- `nltk <= 3.10.3`

Source: https://github.com/advisories/GHSA-8mgp-746c-j5xp
