DEBIAN-CVE-2026-0846

Source
https://security-tracker.debian.org/tracker/CVE-2026-0846
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-0846.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-0846
Upstream
  • CVE-2026-0846
Published
2026-03-09T20:16:05.703Z
Modified
2026-04-28T20:31:04.784732Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability in the filestring() function of the nltk.util module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified by user input without sanitization, enabling attackers to access sensitive system files by providing absolute paths or traversal paths. This vulnerability can be exploited locally or remotely, particularly in scenarios where the function is used in web APIs or other interfaces that accept user-supplied input.

References

Affected packages

Debian:11 / nltk

Package

Name
nltk
Purl
pkg:deb/debian/nltk?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.5-1
3.6.5-1
3.6.7-1
3.7-1
3.8-1
3.8.1-1
3.9.1-1
3.9.1-2
3.9.2-1
3.9.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-0846.json"

Debian:12 / nltk

Package

Name
nltk
Purl
pkg:deb/debian/nltk?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.8-1
3.8.1-1
3.9.1-1
3.9.1-2
3.9.2-1
3.9.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-0846.json"

Debian:13 / nltk

Package

Name
nltk
Purl
pkg:deb/debian/nltk?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.9.1-2
3.9.2-1
3.9.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-0846.json"

Debian:14 / nltk

Package

Name
nltk
Purl
pkg:deb/debian/nltk?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.3-1

Affected versions

3.*
3.9.1-2
3.9.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-0846.json"