CVE-2026-62385: NLTK: Stable FrameNet and NKJP readers parse outside-root XML
Published nltk==3.9.4 still contains several XML-reader entrypoints that build parser paths from caller-controlled selectors or trusted-looking index state without preserving the corpus-root boundary.
References
- github.com/advisories/GHSA-568f-pv23-39p4
- github.com/nltk/nltk/commit/7d1389d0789c1eca56bd0ed444089e0a3972e3ed
- github.com/nltk/nltk/commit/bf3bf32786791394a1008258b4917a7f2d4dbcda
- github.com/nltk/nltk/pull/3579
- github.com/nltk/nltk/pull/3581
- github.com/nltk/nltk/releases/tag/v3.10.0
- github.com/nltk/nltk/security/advisories/GHSA-568f-pv23-39p4
- github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3728.yaml
- nvd.nist.gov/vuln/detail/CVE-2026-62385
- www.vulncheck.com/advisories/nltk-path-traversal-via-framenet-and-nkjp-readers
Code Behaviors & Features
Detect and mitigate CVE-2026-62385 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →