CVE-2026-62388: NLTK Insecure Default Configuration in pathsec.py Allows Path Traversal and Pickle Deserialization Bypass
A vulnerability in NLTK versions before 3.10.0 allows attackers to bypass path traversal and pickle deserialization protections due to insecure default configuration. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. Affected users should update NLTK to version 3.10.0 or later.