Skip to content

[Docs]: Bump nltk once a patch for CVE-2026-81726 is released #533

Description

@keraron

Issue Description

Dependabot alert 159 (CVE-2026-81726 / GHSA-8mgp-746c-j5xp) is a path-sandbox bypass in nltk model-artifact APIs. We are already on the latest release, 3.10.3, which is still in the affected range (<= 3.10.3). No patched version exists yet.

The alert was dismissed as tolerable risk: this is a MkDocs docs build, not an app that enables pathsec or accepts untrusted model paths.

https://github.com/agntcy/docs/security/dependabot/159

Prposed Solution

When nltk ships 3.10.4+ (or another release that lists this CVE as fixed), bump nltk in mkdocs/pyproject.toml and refresh mkdocs/uv.lock.

Affected Component

Other

Checklist

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions