VDB

CVE-2026-0846

CVE-2026-0846 PUBLISHED CVSS 8.600000381469727 HIGH

A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input.

EPSS 0.09% · 25.2th percentile

Risk Scores

CVSS 3.0
8.600000381469727
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
EPSS Score
0.09%
25.2th percentile

Affected Products

VendorProductVersions
nltknltk/nltk*, unspecified, unspecified

Timeline

  • Mar 9, 2026 CVE Published
  • Mar 9, 2026 PoC Published
  • Mar 9, 2026 PoC Published
  • Mar 10, 2026 EPSS Score
  • Mar 11, 2026 EPSS Score
  • Mar 12, 2026 EPSS Score
  • Mar 13, 2026 EPSS Score
  • Mar 14, 2026 EPSS Score
  • Mar 15, 2026 EPSS Score
  • Mar 16, 2026 EPSS Score
  • Mar 17, 2026 EPSS Score
  • Mar 19, 2026 EPSS Score

References

…and 11 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›