NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

Project Subscriptions

Vendors Products
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-p3m8-78j2-g5p3 NLTK: Default ENFORCE=False Disables All pathsec Security Controls
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 31 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Sat, 29 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Title NLTK before 3.10.0 Insecure Default Configuration pathsec NLTK before 3.10.0 Insecure Default Configuration in pathsec.py

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 22 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.
Title NLTK before 3.10.0 Insecure Default Configuration pathsec
First Time appeared Nltk
Nltk nltk
Weaknesses CWE-1188
CPEs cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*
Vendors & Products Nltk
Nltk nltk
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-29T11:47:32.048Z

Reserved: 2026-07-13T22:40:54.412Z

Link: CVE-2026-62388

cve-icon Vulnrichment

Updated: 2026-08-26T17:54:05.012Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-22T15:16:18.967

Modified: 2026-08-27T19:54:52.643

Link: CVE-2026-62388

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-22T14:12:38Z

Links: CVE-2026-62388 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T16:30:05Z

Weaknesses