Skip to main content
EPSS 0.5%top 58%

Gptline: NLTK: Default ENFORCE=False Disables All pathsec Security Controls (CVE-2026-62388)

0
Medium
Published: 08/28/2026 (08/28/2026, 12:34:21 UTC)
Source: GCVE Database
Product: gptline

Description

NLTK's pathsec.py security module defaults to ENFORCE=False, causing all security validation functions to emit warnings instead of raising exceptions on violations. This disables the security protections introduced to fix prior vulnerabilities CVE-2024-39705 and CVE-2026-0846 by default. As a result, unsafe operations like reading sensitive files or loading unsafe pickle data proceed with only warnings, leaving users vulnerable unless they manually enable enforcement via an environment variable. The recommended fix is to change the default to ENFORCE=True to ensure fail-secure behavior.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected software

nltk
pkg:pypi/nltk
Affected versions
<3.10.0
Homebrewmore threats →ghsa
gptline
pkg:brew/gptline
Affected versions
>=1.0.8 <1.0.8_22

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 02:17:48 UTC

Technical Analysis

The NLTK library's pathsec.py module, introduced to mitigate arbitrary code execution and path traversal vulnerabilities (CVE-2024-39705 and CVE-2026-0846), defaults its ENFORCE flag to False. This means that instead of raising exceptions on security violations, the module only emits RuntimeWarnings, allowing potentially unsafe operations such as reading sensitive files or loading untrusted pickle data to succeed. The security controls are effectively opt-in rather than opt-out, undermining their purpose. Users must explicitly set the environment variable NLTK_PATHSEC_ENFORCE=1 to enable enforcement. The suggested remediation is to change the default to ENFORCE=True, making the security checks fail-secure by default.

Potential Impact

Because the security enforcement is disabled by default, users of NLTK versions prior to 3.10.0 who rely on the pathsec module for protection remain vulnerable to arbitrary file reads, unsafe pickle deserialization, and path traversal attacks. This undermines the fixes for CVE-2024-39705 and CVE-2026-0846, potentially allowing attackers to bypass security controls without triggering exceptions, only warnings. This can lead to unauthorized data access and code execution risks if unsafe data sources are used.

Mitigation Recommendations

A patch is available to change the default behavior of the pathsec module to ENFORCE=True, enabling security enforcement by default. Users should apply this patch or upgrade to a fixed version where enforcement is enabled by default. Until then, users can manually enable enforcement by setting the environment variable NLTK_PATHSEC_ENFORCE=1 to activate security exceptions. This ensures that violations raise exceptions rather than just warnings, restoring the intended security protections.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-8vh5-mgjj-w6hg
Osv Schema Version
1.4.0
Aliases
["CVE-2026-62388"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a8a27f9acd9273b499bc9ca

Added to database: 08/22/2026, 22:51:37 UTC

Last enriched: 09/18/2026, 02:17:48 UTC

Last updated: 10/05/2026, 06:48:17 UTC

Views: 87

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses