云虫漏洞情报

CVE-2026-62388 - NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled. - 漏洞详情

漏洞编号:CVE-2026-62388

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-62388

CNNVD 编号:-

厂商/产品:nltk / nltk

影响范围:cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*

CWE:CWE-1188

发布/更新时间:2026-08-22 / 2026-08-27

漏洞描述

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.

相关链接

相关漏洞

« 返回首页