CVE-2026-65915
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-284
Control de acceso incorrecto
Fecha de publicación:
22/08/2026
Última modificación:
24/08/2026
Descripción
*** Pendiente de traducción *** NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check permanently inert. Attackers can pass file:// URLs to nltk.data.load() to read arbitrary files accessible to the process user, including credentials and configuration files.
Impacto
Puntuación base 4.0
7.10
Gravedad 4.0
ALTA
Puntuación base 3.x
6.50
Gravedad 3.x
MEDIA


