CVE-2026-0846
highCVSS v3 Base Score
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Report
Generated by CyberWatcher
Description
A flaw was found in the `nltk` component. This vulnerability, specifically within the `filestring()` function of the `nltk.util` module, allows an attacker to perform arbitrary file reads. By providing specially crafted input paths, either absolute or using directory traversal, an attacker can bypass input validation and access sensitive system files. This can be exploited both locally and remotely, particularly when the function processes user-supplied input in applications like web APIs.
CWE
CWE-22Affected Products
Lightspeed CoreOpenShift LightspeedRed Hat Ansible Automation Platform 2Red Hat OpenShift AI (RHOAI)