PT-2026-82622 · Pypi · Nltk

CVE-2026-81727

·

Published

2026-08-12

·

Updated

2026-09-02

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions NLTK versions prior to 3.10.3
Description A filesystem containment bypass exists in the Downloader.download() and Downloader.incr download() methods. Attackers with write access to a shared downloader directory can create hardlinks pointing to files outside the installation root. During normal package extraction, these hardlinks allow the overwriting of files outside the intended install tree, leading to unauthorized file mutation.
Recommendations Update NLTK to version 3.10.3 or later.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13263
CVE-2026-81727
ECHO-D083-FBC5-4389
GHSA-4XW3-JF9X-X7MF
GHSA-F794-5JV7-7672
PYSEC-2026-3741

Affected Products

Nltk