Issue Description
Dependabot alert 159 (CVE-2026-81726 / GHSA-8mgp-746c-j5xp) is a path-sandbox bypass in nltk model-artifact APIs. We are already on the latest release, 3.10.3, which is still in the affected range (<= 3.10.3). No patched version exists yet.
The alert was dismissed as tolerable risk: this is a MkDocs docs build, not an app that enables pathsec or accepts untrusted model paths.
https://github.com/agntcy/docs/security/dependabot/159
Prposed Solution
When nltk ships 3.10.4+ (or another release that lists this CVE as fixed), bump nltk in mkdocs/pyproject.toml and refresh mkdocs/uv.lock.
Affected Component
Other
Checklist
Issue Description
Dependabot alert 159 (CVE-2026-81726 / GHSA-8mgp-746c-j5xp) is a path-sandbox bypass in nltk model-artifact APIs. We are already on the latest release, 3.10.3, which is still in the affected range (<= 3.10.3). No patched version exists yet.
The alert was dismissed as tolerable risk: this is a MkDocs docs build, not an app that enables pathsec or accepts untrusted model paths.
https://github.com/agntcy/docs/security/dependabot/159
Prposed Solution
When nltk ships 3.10.4+ (or another release that lists this CVE as fixed), bump
nltkinmkdocs/pyproject.tomland refreshmkdocs/uv.lock.Affected Component
Other
Checklist