Junglewise Threat Intelligence

NLTK symlink-based arbitrary file read in IPIPANCorpusReader

Severity: low · CVSS 3.1 · Published 2026-08-22

Technologies: NLTK Project Natural Language Toolkit. Vendors: NLTK Project.

Executive brief

NLTK is a widely-used natural language processing library. A vulnerability in its IPIPANCorpusReader component allows attackers who can place symbolic links (symlinks) in a corpus directory to read arbitrary files accessible to the process. This could expose sensitive data if NLTK is used to process corpora in shared environments or untrusted directories.

Technical details

The vulnerability is a symlink-based path traversal (CWE-22/CWE-59) in IPIPANCorpusReader methods (channels(), domains(), categories(), fileids()). The root cause is in _get_tag(), which converts a FileSystemPathPointer object to a plain Python string via .replace(), losing the PathPointer wrapper and all pathsec validation. The resulting string is passed directly to builtin open() with no nltk.pathsec.validate_path() check. An attacker with ability to plant a symlink in the corpus root directory can trigger arbitrary file reads by calling any of these methods with the symlink filename. Literal ../ traversal is still blocked, making this specifically a symlink vulnerability. Fixed in version 3.10.2; versions 3.10.0 and 3.10.1 are affected.

Affected products

  • NLTK Project NLTK 3.10.0, 3.10.1

Timeline

  • 2026-08-07: disclosed
  • 2026-08-22: patched: version 3.10.2

References