NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.
History

Mon, 31 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Sat, 29 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Title NLTK before 3.10.0 Insecure Default Configuration pathsec NLTK before 3.10.0 Insecure Default Configuration in pathsec.py

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 22 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.
Title NLTK before 3.10.0 Insecure Default Configuration pathsec
First Time appeared Nltk
Nltk nltk
Weaknesses CWE-1188
CPEs cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*
Vendors & Products Nltk
Nltk nltk
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-08-22T14:12:38.647Z

Updated: 2026-08-29T11:47:32.048Z

Reserved: 2026-07-13T22:40:54.412Z

Link: CVE-2026-62388

cve-icon Vulnrichment

Updated: 2026-08-26T17:54:05.012Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-22T15:16:18.967

Modified: 2026-08-27T19:54:52.643

Link: CVE-2026-62388

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-22T14:12:38Z

Links: CVE-2026-62388 - Bugzilla