CVE-2026-0846
published 2026-03-09CVE-2026-0846: A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input…
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.43%
34.7th percentile
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nltk | < nltk 3.9.3-1 (forky) | nltk 3.9.3-1 (forky) |
| nltk | nltk | — | — |
| nltk | nltk | >= 0 < 3.9.3-1 | 3.9.3-1 |
| nltk | nltk | >= 0 < 3.9.3 | 3.9.3 |
| nltk | nltk_nltk | unspecified – latest | — |
| ubuntu | nltk | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
nltk up to 3.9.2 nltk.util filestring absolute path traversal (Nessus ID 316734)
vuldb·2026-05-26·CVSS 8.6
CVE-2026-0846 [HIGH] nltk up to 3.9.2 nltk.util filestring absolute path traversal (Nessus ID 316734)
A vulnerability was found in nltk up to 3.9.2 and classified as critical. Affected by this issue is the function filestring of the component nltk.util. The manipulation results in absolute path traversal.
This vulnerability was named CVE-2026-0846. The attack may be performed from remote. There is no available exploit.
OSV
CVE-2026-0846: A vulnerability in the `filestring()` function of the `nltk
osv·2026-03-09·CVSS 8.6
CVE-2026-0846 [HIGH] CVE-2026-0846: A vulnerability in the `filestring()` function of the `nltk
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input.
GHSA
GHSA-h8wq-7xc4-p3qx: A vulnerability in the `filestring()` function of the `nltk
ghsa_unreviewed·2026-03-09
CVE-2026-0846 [HIGH] CWE-36 GHSA-h8wq-7xc4-p3qx: A vulnerability in the `filestring()` function of the `nltk
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input.
GHSA
NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()
ghsa·2026-03-09
CVE-2026-0846 [HIGH] CWE-36 NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()
NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input.
Ubuntu
NLTK vulnerabilities
vendor_ubuntu·2026-05-25·CVSS 8.6
CVE-2026-33230 [HIGH] NLTK vulnerabilities
Title: NLTK vulnerabilities
Summary: Several security issues were fixed in NLTK.
It was discovered that NLTK incorrectly validated file paths when
opening files using the nltk.util module. An attacker could possibly
use this issue to obtain sensitive information. (CVE-2026-0846)
It was discovered that NLTK incorrectly validated file paths in
multiple CorpusReader classes. An attacker could possibly use
this issue to obtain sensitive information. (CVE-2026-0847)
It was discovered that NLTK did not properly validate external
Java archive files loaded by StanfordSegmenter. An attacker
could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu
22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-0848)
It was discove
Red Hat
nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function
vendor_redhat·2026-03-09·CVSS 8.6
CVE-2026-0846 [HIGH] CWE-22 nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function
nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input.
A flaw was found in the `nltk` component. This vulnerability, specifically within the `filestring()` function of the `nltk.util` module, allows an attacker to perform arbitrary file reads. B
Debian
CVE-2026-0846: nltk - A vulnerability in the `filestring()` function of the `nltk.util` module in nltk...
vendor_debian·2026·CVSS 8.6
CVE-2026-0846 [HIGH] CVE-2026-0846: nltk - A vulnerability in the `filestring()` function of the `nltk.util` module in nltk...
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.9.3-1)
sid: resolved (fixed in 3.9.3-1)
trixie: open
No detection rules found.
No public exploits indexed.
https://huntr.com/bounties/007b84f8-418e-4300-99d0-bf504c2f97ebhttps://access.redhat.com/errata/RHSA-2026:10184https://access.redhat.com/errata/RHSA-2026:19712https://access.redhat.com/security/cve/CVE-2026-0846https://bugzilla.redhat.com/show_bug.cgi?id=2445826https://huntr.com/bounties/007b84f8-418e-4300-99d0-bf504c2f97ebhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0846.json
2026-03-09
Published