Files Overwrite Vulnerability in NLTK Product by NLTK
CVE-2026-81727

6.9MEDIUM

Key Information:

Vendor

Nltk

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-81727?

Versions of NLTK prior to 3.10.3 are susceptible to a filesystem containment bypass vulnerability. This issue arises within the Downloader.download and Downloader.incr_download methods, allowing attackers to overwrite files located outside the designated installation directory through pre-existing hardlinks. When attackers gain write access to a shared downloader directory, they can create hardlinks that point to files outside the intended root directory. This results in the modification of files during standard package extraction processes, leading to significant risks for file integrity.

Affected Version(s)

nltk 0 < 3.10.3

nltk 3.10.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.