Security Advisory

CVE-2026-81726

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-27 14:51:18
Last updated 2026-08-27 14:51:18
Assigner VulnCheck
CVSS score 8.3
State PUBLISHED

Description

NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.