Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-62388

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path traversal and pickle deserialization protections by exploiting the disabled security controls that are only active when manually enabled.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 25.9%
CVSS Severity
CVSS v3 Score 7.5


Contact Us

Shodan ® - All rights reserved