CVE-2026-79674
NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader constructors to access filesystem content and SQLite databases outside the pathsec sandbox boundary.
- Affected products
- Nltk
- Fix
- Available
- CVSS 4.0
- 8.8 HIGH
- CVSS 3.1
- 8.2 HIGH
- Weakness
- CWE-73
- NVD status
- Received
- Published
- 2026-08-25
CVE-2026-79674 at NVD
No indexed exploits for CVE-2026-79674 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-79674 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.