Gptline: NLTK: Stable FrameNet and NKJP readers parse outside-root XML (CVE-2026-62385)
Description
NLTK version 3.9.4 contains a path traversal vulnerability in its FrameNet and NKJP corpus readers. The issue allows XML parsing outside the intended corpus root directory by using unsafe selectors or poisoned index state. This vulnerability is patched in version 3.10.0, which enforces path-safety checks to prevent such traversal. Applications that process attacker-controlled corpus selectors or state may inadvertently parse XML files outside the trusted corpus root.
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in NLTK 3.9.4 affects several XML-reader entrypoints in FrameNet and NKJP corpus readers, including FramenetCorpusReader.frame_by_name, doc, lu, and NKJPCorpusReader.header. These readers construct parser paths from caller-controlled selectors or poisoned index state without enforcing corpus-root boundary confinement, enabling path traversal and trusted-root bypass. The flaw allows parsing of XML files located outside the trusted corpus root. The issue is confirmed by proof-of-concept tests and is fixed in NLTK 3.10.0, which rejects unsafe path components and enforces path-safety. The vulnerability has a CVSS 3.1 score of 5.9 (medium severity) with network attack vector, high attack complexity, no privileges required, no user interaction, and impact on confidentiality only.
Potential Impact
Applications using vulnerable NLTK versions (3.9.4) that accept attacker-influenced FrameNet or NKJP corpus selectors or index state can be tricked into parsing XML files outside the trusted corpus root. This can lead to unauthorized disclosure of file contents (confidentiality impact). There is no impact on integrity or availability. The vulnerability requires network access and has high attack complexity, with no privileges or user interaction needed.
Mitigation Recommendations
A patch is available in NLTK version 3.10.0, which enforces path-safety by rejecting unsafe path components before constructing filenames from frame names, document filenames, LU ids, or NKJP file identifiers. Users should upgrade to version 3.10.0 or later to mitigate this vulnerability. Until upgraded, applications should avoid processing untrusted selectors or index state with the affected reader APIs.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qp76-pq9f-gr9m
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-62385"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a8a27f7acd9273b499bc986
Added to database: 08/22/2026, 22:51:35 UTC
Last enriched: 09/18/2026, 02:17:53 UTC
Last updated: 10/07/2026, 18:48:21 UTC
Views: 73
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.