Explore top 10 tips to secure your open-source projects now. Read More
×
Description:
URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local
File Read. (CVE-2026-54293)
- https://bugs.mageia.org/show_bug.cgi?id=35762
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/WMWF7SLMCGEL35KSK5ERA7U5CKTU5Z57/
- https://github.com/nltk/nltk/security/advisories/GHSA-p4gq-832x-fm9v
- https://www.cve.org/CVERecord?id=CVE-2026-54293
- 10/core/python-nltk-3.9.4-1.1.mga10
- 9/core/python-nltk-3.9.4-1.1.mga9
Publication date:20 Jul 2026
Get the latest Linux and open source security news straight to your inbox.