Link following in Natural Language Toolkit - #VU141415
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper link resolution before file access in FramenetCorpusReader when resolving corpus file paths through symlinks. A remote attacker can place a symlink inside a corpus subdirectory and invoke a normal public API call to disclose sensitive information.
Exploitation requires a tampered or shared corpus directory, and no user interaction is required.