CVE-2026-81726
NLTK through 3.10.3 contains a path traversal vulnerability in model-artifact APIs that bypass pathsec enforcement by using raw file operations on caller-controlled paths. Attackers can read or write files outside allowed sandbox roots through TransitionParser, AveragedPerceptron, PerceptronTagger, and maxent parameter APIs when pathsec is enabled.
- Published Aug 27, 2026
- CVSS 8.3 high
- 0.3% chance of exploitation in the next 30 days (EPSS)
- Public exploit code is available