CVE-2026-81727 MEDIUM

CVE-2026-81727: NLTK before 3.10.3 Hardlink File Overwrite via downloader

Vendor Nltk
Product nltk
Weakness CWE-59
Published August 27, 2026
Last update August 27, 2026

CVSS base score

6.9/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 27, 2026 Record updated