cbcvebase.
CVE-2026-0846
published 2026-03-09

CVE-2026-0846: A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input…

PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.43%
34.7th percentile
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input.

Affected

6 ranges
VendorProductVersion rangeFixed in
debiannltk< nltk 3.9.3-1 (forky)nltk 3.9.3-1 (forky)
nltknltk
nltknltk>= 0 < 3.9.3-13.9.3-1
nltknltk>= 0 < 3.9.33.9.3
nltknltk_nltkunspecified – latest
ubuntunltk

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.