Path traversal in Natural Language Toolkit - #VU141247

 

Path traversal in Natural Language Toolkit - #VU141247

Published: August 7, 2026


Vulnerability identifier: #VU141247
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in FramenetCorpusReader.frame_by_name, FramenetCorpusReader.doc, FramenetCorpusReader.lu, and NKJPCorpusReader.header when parsing caller-controlled selectors or trusted-looking index state into XML file paths. A remote attacker can supply crafted selectors, poisoned index state, or unsafe file identifiers to disclose sensitive information.

Exploitation requires the application to expose FrameNet or NKJP reader APIs and trust them to confine XML parsing to a corpus root.


Affected software

Natural Language Toolkit

Remediation

Install security update from vendor's website.

Natural Language Toolkit - update to 3.10.0

External References

Related Security Bulletins