Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree. | |
| Title | NLTK before 3.10.3 Hardlink File Overwrite via downloader | |
| First Time appeared |
Nltk
Nltk nltk |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nltk
Nltk nltk |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-27T14:51:19.564Z
Reserved: 2026-08-27T11:15:29.420Z
Link: CVE-2026-81727
No data.
Status : Received
Published: 2026-08-27T17:21:03.533
Modified: 2026-08-27T17:21:03.533
Link: CVE-2026-81727
No data.
OpenCVE Enrichment
No data.