Gptline: NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely (CVE-2026-62383)
Description
The IPIPANCorpusReader component of the NLTK library contains a vulnerability allowing local attackers with write access to the corpus directory to read arbitrary files via symlink-based traversal. This occurs because certain public methods open files using Python's builtin open() without path validation, bypassing NLTK's pathsec protections. The flaw permits reading files outside the corpus root if a symlink is planted with a suitable name. Exploitation requires local filesystem access to place symlinks but no elevated privileges or user interaction. A patch is available to route file access through proper path validation.
CVSS v3.1
Score 5.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The IPIPANCorpusReader in NLTK exposes methods (channels(), domains(), categories(), fileids()) that accept user-supplied file IDs and open files using Python's builtin open() without invoking nltk.pathsec validation. This allows a symlink placed inside the corpus root with a benign name to bypass traversal checks and read arbitrary files anywhere accessible by the process. The vulnerability is a variant of CWE-22 (path traversal) exploiting symlink resolution, distinct from prior fixes that enforced pathsec validation. The issue arises because PathPointer objects are converted to plain strings before opening, skipping validation. Proof-of-concept code demonstrates reading a file outside the corpus root via a symlink named 'evil_link.xml'. The CVSS 3.1 score is 5.5 (medium severity) with local attack vector and high confidentiality impact. The recommended fix is to route file opening through nltk.pathsec.validate_path() or CorpusReader.open() to enforce corpus root constraints.
Potential Impact
An attacker with local write access to the corpus directory can create symlinks that cause the IPIPANCorpusReader to read arbitrary files outside the intended corpus root. This leads to unauthorized disclosure of sensitive files accessible by the process. There is no impact on integrity or availability, and no elevated privileges are required beyond the ability to place symlinks locally. The vulnerability does not require user interaction and executes with the same privileges as the running process.
Mitigation Recommendations
A patch is available to fix this vulnerability. The fix involves modifying the _get_tag() method to route file opening through nltk.pathsec.validate_path() with the corpus root as a required root or through CorpusReader.open(), instead of calling Python's builtin open() on a plain string path. Users should apply the official patch or upgrade to a fixed version to ensure path validation is enforced and symlink-based arbitrary file reads are prevented.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-343m-9fqq-97c7
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-62383"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a8a27f9acd9273b499bc9d2
Added to database: 08/22/2026, 22:51:37 UTC
Last enriched: 09/18/2026, 02:18:09 UTC
Last updated: 10/06/2026, 18:48:23 UTC
Views: 106
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.