Nltk Nltk Vulnerabilities

3 advisories affecting Nltk Nltk

3

Total CVEs

1

Critical

2

High

CVE-2026-0846

Mar 9, 2026

High (8.6)

A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files s...

Read Advisory

CVE-2026-0847

Mar 4, 2026

High (8.6)

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and Brack...

Read Advisory

CVE-2025-14009

Feb 18, 2026

Critical (10.0)

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path ...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.