{"id":"GHSA-p3m8-78j2-g5p3","summary":"NLTK: Default ENFORCE=False Disables All pathsec Security Controls","details":"NLTK's pathsec.py security module defaults to ENFORCE=False (line 24), which means all 8 security validation functions only emit RuntimeWarning instead of raising exceptions when violations are detected.\n\nThe pathsec module was introduced as the fix for CVE-2024-39705 (arbitrary code execution via pickle) and CVE-2026-0846 (path traversal). However, with ENFORCE=False as the default:\n\n1. pathsec.open('/etc/passwd') succeeds (reads the file, emits warning)\n2. pathsec.validate_network_url('http://169.254.169.254/...') succeeds (warning only)\n3. pickle.loads() via nltk.data.load() proceeds despite unsafe source (warning only)\n\nEvery security gate follows the same pattern:\n```python\nENFORCE = os.environ.get('NLTK_PATHSEC_ENFORCE', '').lower() in ('1', 'true', 'yes')\n\ndef validate_something(path):\n    if is_violation(path):\n        if ENFORCE:\n            raise SecurityError('...')  # Only raised when env var is set\n        else:\n            warnings.warn('...', RuntimeWarning)  # Default: warning only\n    # Execution continues regardless\n```\n\nThis means the security remediations for CVE-2024-39705 and CVE-2026-0846 are effectively disabled by default. Any user who installed NLTK 3.9.x expecting the security fixes to be active is still vulnerable unless they manually set NLTK_PATHSEC_ENFORCE=1.\n\nPoC:\n```python\nimport nltk.pathsec\nimport warnings\n\n# Show that ENFORCE is False by default\nprint(f'ENFORCE = {nltk.pathsec.ENFORCE}')  # False\n\n# Attempt to read /etc/passwd through pathsec -- should be blocked\nwith warnings.catch_warnings(record=True) as w:\n    warnings.simplefilter('always')\n    result = nltk.pathsec.open('/etc/passwd', 'r')\n    print(f'File opened: {result.name}')  # /etc/passwd\n    print(f'Warning emitted: {w[0].message}')  # RuntimeWarning (not an exception)\n    # Attack succeeds -- file is readable\n```\n\nThe correct default is fail-secure: ENFORCE should be True unless explicitly disabled. The current default makes the security module opt-in rather than opt-out, defeating its purpose.\n\nSuggested fix: Change default to ENFORCE=True. Users who need backwards compatibility can set NLTK_PATHSEC_ENFORCE=0 to explicitly disable.","aliases":["CVE-2026-62388","PYSEC-2026-3722"],"modified":"2026-09-02T16:00:17.572328596Z","published":"2026-09-02T15:40:33Z","database_specific":{"github_reviewed_at":"2026-09-02T15:40:33Z","nvd_published_at":null,"cwe_ids":["CWE-1188"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/nltk/nltk/security/advisories/GHSA-p3m8-78j2-g5p3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62388"},{"type":"WEB","url":"https://github.com/nltk/nltk/pull/3593"},{"type":"WEB","url":"https://github.com/nltk/nltk/commit/155e40343cff0bf50d233e274a12e04d1428b1d9"},{"type":"PACKAGE","url":"https://github.com/nltk/nltk"},{"type":"WEB","url":"https://github.com/nltk/nltk/releases/tag/v3.10.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3722.yaml"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/nltk-before-insecure-default-configuration-pathsec"}],"affected":[{"package":{"name":"nltk","ecosystem":"PyPI","purl":"pkg:pypi/nltk"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.10.0"}]}],"versions":["0.8","0.9","0.9.3","0.9.4","0.9.5","0.9.6","0.9.7","0.9.8","0.9.9","2.0.1","2.0.1rc1","2.0.1rc2-git","2.0.1rc3","2.0.1rc4","2.0.2","2.0.3","2.0.4","2.0.5","2.0b4","2.0b5","2.0b6","2.0b7","2.0b8","2.0b9","3.0.0","3.0.0b1","3.0.0b2","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.1","3.2","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.3","3.4","3.4.1","3.4.2","3.4.3","3.4.4","3.4.5","3.5","3.5b1","3.6","3.6.1","3.6.2","3.6.3","3.6.4","3.6.5","3.6.6","3.6.7","3.7","3.8","3.8.1","3.9","3.9.1","3.9.2","3.9.3","3.9.4","3.9b1"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.9.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-p3m8-78j2-g5p3/GHSA-p3m8-78j2-g5p3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}