CVE-2026-70626: NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root
nltk.corpus.reader.api.CorpusReader.open() can be used to read files outside the intended corpus root via a symlink placed inside that root. Although NLTK blocks absolute paths and .. traversal, the current boundary check is only lexical and does not account for symlink resolution. This leads to an arbitrary local file read / filesystem sandbox bypass for applications that rely on CorpusReader or FileSystemPathPointer to restrict file access.
References
- github.com/advisories/GHSA-r6gq-whwq-mvg9
- github.com/nltk/nltk/commit/1b0e519e2324bc1a273d56edee63e44d0ad85b48
- github.com/nltk/nltk/pull/3522
- github.com/nltk/nltk/releases/tag/3.9.4
- github.com/nltk/nltk/security/advisories/GHSA-r6gq-whwq-mvg9
- github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3732.yaml
- nvd.nist.gov/vuln/detail/CVE-2026-70626
- www.vulncheck.com/advisories/nltk-before-symlink-escape-via-corpusreader
Code Behaviors & Features
Detect and mitigate CVE-2026-70626 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →