Path traversal in Natural Language Toolkit - CVE-2026-33236
Published: August 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to overwrite arbitrary files.
The vulnerability exists due to path traversal in the downloader component when processing user-supplied download paths. A remote attacker can supply a specially crafted path to overwrite arbitrary files.
User interaction is required to initiate the download process.