Gptline: NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read (CVE-2026-63312)
Description
NLTK's StreamBackedCorpusView bypasses the pathsec.ENFORCE sandboxing intended to restrict file access. When ENFORCE is set to True, file access should be limited to allowed NLTK data directories, but StreamBackedCorpusView opens files directly using builtins.open(), ignoring pathsec validation. This allows an attacker controlling the fileid argument to read arbitrary local files. The issue affects StreamBackedCorpusView, XMLCorpusView, and corpus readers passing raw string fileids. A fix is available to replace direct file operations with pathsec-validated calls.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-63312) in NLTK arises because StreamBackedCorpusView._open() and related code bypass the pathsec.validate_path() enforcement when opening files, even if nltk.pathsec.ENFORCE is set to True. This allows arbitrary local file read by passing a malicious file path as the fileid parameter. The enforcement function in pathsec.py calls validate_path() before opening files, but StreamBackedCorpusView directly calls builtins.open() and os.stat() on string fileids, ignoring the sandbox. This flaw affects any corpus reader subclass that uses StreamBackedCorpusView with raw string fileids. The vulnerability is confirmed on the latest stable NLTK versions and requires no privileges.
Potential Impact
This vulnerability enables arbitrary local file read on affected systems, bypassing the intended sandboxing controls of nltk.pathsec.ENFORCE. Attackers can read sensitive files such as /etc/passwd, /proc/self/environ (which may contain environment secrets), and application configuration files. This represents a broken access control issue (OWASP A01:2021) and CWE-22 (Path Traversal) and CWE-284 (Improper Access Control). It affects web applications, REST APIs, and multi-tenant NLP pipelines that pass user-controlled input to NLTK corpus readers, potentially exposing sensitive data without requiring any privileges.
Mitigation Recommendations
A patch is available for this vulnerability. The recommended fix is to modify StreamBackedCorpusView and related corpus readers to replace direct calls to builtins.open() and os.stat() with calls to nltk.pathsec.open() and nltk.pathsec.validate_path(), ensuring enforcement of the sandbox. Operators should apply the official patch or update to a fixed version as soon as possible. Until patched, avoid passing untrusted user input directly as fileid to corpus readers that use StreamBackedCorpusView.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-8w48-h75v-cxpv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-63312"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a8a27f6acd9273b499bc945
Added to database: 08/22/2026, 22:51:34 UTC
Last enriched: 09/18/2026, 02:17:38 UTC
Last updated: 10/06/2026, 18:48:23 UTC
Views: 50
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.