nltk/nltk vulnerabilities
CVEs whose affected-version data names the nltk/nltk package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-0846High· 8.6PoCArbitrary File Read via Absolute Path Input in nltk.util.filestring()
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without saniti…
▾ Midnightnltk · nltk/nltkEPSS 0.43%via CVEORG
CVE-2026-0847High· 8.6PoCPath Traversal in nltk/nltk
A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classes fa…
▾ Midnightnltk · nltk/nltkEPSS 0.90%via CVEORG