External Control of File Name or Path in Natural Language Toolkit - #VU142780

 

External Control of File Name or Path in Natural Language Toolkit - #VU142780

Published: August 15, 2026 / Updated: August 18, 2026


Vulnerability identifier: #VU142780
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read or overwrite files outside allowed roots.

The vulnerability exists due to external control of file name or path in model-artifact APIs when handling caller-controlled model import or export paths. A remote attacker can provide a crafted path to read or overwrite files outside allowed roots.

Exploitation requires an application to enable path security enforcement and allow untrusted workflows to choose model import or export paths.


Affected software

Natural Language Toolkit

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins