CVE-2026-0847 - Vulnerability Analysis
HighCVSS: 8.6Last Updated: March 4, 2026
NLTK - Path Traversal
Published: March 4, 2026Updated: March 4, 2026Remote Exploitable
Overview
NLTK <= 3.9.2 contains a path traversal vulnerability caused by improper sanitization of file paths in multiple CorpusReader classes, letting attackers read arbitrary files, exploit requires user-controlled file inputs.
Severity & Score
Severity: High
CVSS Score: 8.6
Impact
Attackers can read sensitive files, potentially leading to information disclosure and further exploitation.
Mitigation
Update to the latest version beyond 3.9.2.
Related Resources
Details
- CVE ID
- CVE-2026-0847
- Severity
- High
- CVSS Score
- 8.6
- Type
- path_traversal
- Status
- new
CWE
- CWE-22
CVSS Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L