Files Overwrite Vulnerability in NLTK Product by NLTK
CVE-2026-81727
6.9MEDIUM
What is CVE-2026-81727?
Versions of NLTK prior to 3.10.3 are susceptible to a filesystem containment bypass vulnerability. This issue arises within the Downloader.download and Downloader.incr_download methods, allowing attackers to overwrite files located outside the designated installation directory through pre-existing hardlinks. When attackers gain write access to a shared downloader directory, they can create hardlinks that point to files outside the intended root directory. This results in the modification of files during standard package extraction processes, leading to significant risks for file integrity.
Affected Version(s)
nltk 0 < 3.10.3
nltk 3.10.3
