CVE-2026-81726
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
27/08/2026
Last modified:
28/08/2026
Description
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.
Impact
Base Score 4.0
8.30
Severity 4.0
HIGH
Base Score 3.x
7.00
Severity 3.x
HIGH



