CVE-2026-63312
NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control the fileid argument can read arbitrary local files regardless of the ENFORCE setting, including sensitive system files and application credentials.
- Affected products
- Nltk
- Fix
- Available
- CVSS 4.0
- 8.7 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.5% (40th percentile)
- Weakness
- CWE-22
- NVD status
- Received
- Published
- 2026-08-22
CVE-2026-63312 at NVD
No indexed exploits for CVE-2026-63312 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-63312 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.