nltk is vulnerable to Improper Link Resolution Before File Access
52
Medium Risk
FramenetCorpusReader and IPIPANCorpusReader open files reached through caller- or corpus-index-supplied names without resolving symbolic links first. A symlink planted inside the corpus directory under a name that contains no path-traversal characters is silently followed, so the reader can open a file located anywhere on the filesystem the process can reach. The fix resolves links before opening corpus files and keeps reads confined to the intended corpus root.
You are affected if you are using a version that falls within the vulnerable range and your application uses NLTK's FrameNet or IPI PAN corpus readers on a corpus directory where an untrusted party can place a symbolic link.
nltk is vulnerable to Improper Link Resolution Before File Access in versions 2.0.1 - 3.10.1.
Upgrade the nltk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant