Skip to main content
EPSS 0.4%top 66%

Gptline: NLTK: Stable FrameNet and NKJP readers parse outside-root XML (CVE-2026-62385)

0
Medium
Published: 09/02/2026 (09/02/2026, 09:04:31 UTC)
Source: GCVE Database
Product: gptline

Description

NLTK version 3.9.4 contains a path traversal vulnerability in its FrameNet and NKJP corpus readers. The issue allows XML parsing outside the intended corpus root directory by using unsafe selectors or poisoned index state. This vulnerability is patched in version 3.10.0, which enforces path-safety checks to prevent such traversal. Applications that process attacker-controlled corpus selectors or state may inadvertently parse XML files outside the trusted corpus root.

CVSS v3.1

Score 5.9medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected software

nltk
pkg:pypi/nltk
Affected versions
<3.10.0
Homebrewmore threats →ghsa
gptline
pkg:brew/gptline
Affected versions
>=1.0.8 <1.0.8_22

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 02:17:53 UTC

Technical Analysis

The vulnerability in NLTK 3.9.4 affects several XML-reader entrypoints in FrameNet and NKJP corpus readers, including FramenetCorpusReader.frame_by_name, doc, lu, and NKJPCorpusReader.header. These readers construct parser paths from caller-controlled selectors or poisoned index state without enforcing corpus-root boundary confinement, enabling path traversal and trusted-root bypass. The flaw allows parsing of XML files located outside the trusted corpus root. The issue is confirmed by proof-of-concept tests and is fixed in NLTK 3.10.0, which rejects unsafe path components and enforces path-safety. The vulnerability has a CVSS 3.1 score of 5.9 (medium severity) with network attack vector, high attack complexity, no privileges required, no user interaction, and impact on confidentiality only.

Potential Impact

Applications using vulnerable NLTK versions (3.9.4) that accept attacker-influenced FrameNet or NKJP corpus selectors or index state can be tricked into parsing XML files outside the trusted corpus root. This can lead to unauthorized disclosure of file contents (confidentiality impact). There is no impact on integrity or availability. The vulnerability requires network access and has high attack complexity, with no privileges or user interaction needed.

Mitigation Recommendations

A patch is available in NLTK version 3.10.0, which enforces path-safety by rejecting unsafe path components before constructing filenames from frame names, document filenames, LU ids, or NKJP file identifiers. Users should upgrade to version 3.10.0 or later to mitigate this vulnerability. Until upgraded, applications should avoid processing untrusted selectors or index state with the affected reader APIs.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-qp76-pq9f-gr9m
Osv Schema Version
1.4.0
Aliases
["CVE-2026-62385"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a8a27f7acd9273b499bc986

Added to database: 08/22/2026, 22:51:35 UTC

Last enriched: 09/18/2026, 02:17:53 UTC

Last updated: 10/07/2026, 18:48:21 UTC

Views: 73

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses