Critical Symlink-Based Sandbox Bypass in NLTK FramenetCorpusReader (CVE-2026-62384)
CVE-2026-62384 is a critical symlink-based sandbox bypass vulnerability in NLTK's FramenetCorpusReader, affecting versions before 3.10.2. This vulnerability allows attackers to read arbitrary XML files outside the corpus root, with a CVSS score of 7.5. Organizations should immediately upgrade to NLTK version 3.10.2 or later to mitigate this high-severity threat.