GHSA-h8wq-7xc4-p3qx · Severity: high · Ecosystem: pip — NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input.
Conclusion & alert: CVE-2026-0846 is rated Exploit Available (53/100): CVSS High severity, with low exploitation likelihood (EPSS 0.08%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-10 | — | 0.08% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 8.6 | 3.0 | HIGH |
|
3.9 | 4.7 | [email protected] |
GHSA-h8wq-7xc4-p3qx · Severity: high · Ecosystem: pip — NLTK has Arbitrary File Read via Absolute Path Input in nltk.util.filestring()
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-0846 not yet assigned priority: Debian including 1 source packages (nltk), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 3, resolved 2. | https://security-tracker.debian.org/tracker/CVE-2026-0846 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2026-0846 |
suse
|
high | — | https://www.suse.com/security/cve/CVE-2026-0846/ |
ubuntu
|
medium | CVE-2026-0846 medium priority: Ubuntu including 1 source packages (nltk), 8 status rows across 8 suites (bionic, focal, jammy, noble, questing, trusty, upstream, xenial): needed 7, released 1. | https://ubuntu.com/security/CVE-2026-0846 |
| URL | Tags |
|---|---|
| https://huntr.com/bounties/007b84f8-418e-4300-99d0-bf504c2f97eb | Exploit Vendor Advisory |