Junglewise Threat Intelligence

CVE-2026-54293: NLTK path traversal via URL-encoded separators in nltk.data.load

CVE-2026-54293 · Severity: high · CVSS 7.5 · Published 2026-06-22

Technologies: Nltk, NLTK Project Natural Language Toolkit. Vendors: NLTK Project, PyPI.

Executive brief

The Natural Language Toolkit (NLTK), a popular Python library for processing human language data, contains a security flaw that allows unauthorized access to files on the host system. By providing specially crafted, encoded file paths to certain NLTK functions, an attacker can bypass security filters to read sensitive information such as system passwords, API keys, or configuration files. This poses a significant risk to web applications, hosted notebooks, and automated data pipelines that use NLTK to process user-supplied input.

Technical details

A path traversal vulnerability exists in `nltk.data.load()` and `find()` due to a 'decode-after-check' flaw. The library uses a regular expression (`_UNSAFE_NO_PROTOCOL_RE`) to block traversal sequences like '../' and absolute paths, but this check is performed on raw input before URL-decoding occurs. An attacker can bypass this protection by using URL-encoded characters such as '%2f' for slashes or '%2e%2e' for dots. When the `nltk:` URL scheme is processed, `url2pathname()` subsequently decodes these sequences into a valid filesystem path, allowing the retrieval of sensitive files (e.g., /etc/passwd or /proc/self/environ). This issue is resolved in version 3.10.0-rc1 by ensuring inputs are decoded before safety validation.

Affected products

  • nltk nltk < 3.10.0-rc1

Timeline

  • 2026-05-14: other: Pull request to fix the issue submitted
  • 2026-06-06: patched: Fix merged into develop branch
  • 2026-06-11: advisory: GitHub Security Advisory published
  • 2026-06-22: disclosed: CVE published to NVD

References

Related threats