{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-62388","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-07-13T22:40:54.412Z","datePublished":"2026-08-22T14:12:38.647Z","dateUpdated":"2026-08-29T11:47:32.048Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-08-29T11:47:32.048Z"},"datePublic":"2026-08-07T00:00:00.000Z","title":"NLTK before 3.10.0 Insecure Default Configuration in pathsec.py","descriptions":[{"lang":"en","value":"NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Initialization of a Resource with an Insecure Default","cweId":"CWE-1188","type":"CWE"}]}],"affected":[{"vendor":"nltk","product":"nltk","defaultStatus":"unaffected","packageURL":"pkg:pypi/nltk","versions":[{"version":"0","status":"affected","versionType":"semver","lessThan":"3.10.0"},{"version":"3.10.0","status":"unaffected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*","versionEndExcluding":"3.10.0"}]}]}],"metrics":[{"format":"CVSS","cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH"}},{"format":"CVSS","cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}],"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-p3m8-78j2-g5p3","tags":["vendor-advisory"],"name":"GitHub Security Advisory (GHSA-p3m8-78j2-g5p3)"},{"name":"VulnCheck Advisory: NLTK before 3.10.0 Insecure Default Configuration pathsec","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/nltk-before-insecure-default-configuration-pathsec"}],"x_generator":{"engine":"vulncheck-endgame"}},"adp":[{"references":[{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-p3m8-78j2-g5p3","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-26T17:53:47.950536Z","id":"CVE-2026-62388","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-26T17:54:14.495Z"}}]}}