External Control of File Name or Path in Natural Language Toolkit - #VU142780
Published: August 15, 2026 / Updated: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to read or overwrite files outside allowed roots.
The vulnerability exists due to external control of file name or path in model-artifact APIs when handling caller-controlled model import or export paths. A remote attacker can provide a crafted path to read or overwrite files outside allowed roots.
Exploitation requires an application to enable path security enforcement and allow untrusted workflows to choose model import or export paths.