mediumCVSS 7.1Vulnerability

CVE-2026-81727

### Summary NLTK's downloader now blocks symlink escapes during ZIP extraction, but it still treats pre-existing hardlinks inside the install tree as ordinary in-root files. A normal package install can therefore overwrite an outside-root inode through that hardlink. ### Details - **Vulnerability type:** Filesystem containment bypass - **Affected component:** `nltk.downloader.Downloader.download`, `nltk.downloader.Downloader.incr_download` - **Affected versions:** Published `3.9.4` and current source `v3.10.0-rc2` both reproduced for the extraction-stage overwrite. - **Patched versions:** 3.10.3 - **Root cause:** The downloader validates traversal and symlink conditions but does not reject pre-existing hardlink aliases inside the install tree. The install flow correctly rejects a pre-existing symlink at an extraction target, yet it accepts a pre-existing hardlink at the same path. When the package is installed, extracted member data is written through the hardlink and mutates the outside inode. ### PoC **Preconditions** - The attacker can plant files inside a writable shared downloader root on the same filesystem as the target file. **Steps** 1. Prepare a downloader root and create a hardlink inside it that points to an outside target file. 2. Confirm a symlink at the same path is rejected as a negative control. 3. Run a normal `Downloader.download()` package install whose extracted member lands on the hardlink path. 4. Observe the outside target file is overwritten while the downloader still reports the package as installed. **Minimal reproducible excerpt** ```text extract_hardlink_before ORIGINAL extract_hardlink_after PWNED extract_hardlink_status installed ``` ### Impact A shared or attacker-influenced downloader directory can be turned into an overwrite primitive against same-filesystem files outside the intended install root. ### Remediation Treat pre-existing hardlinks as unsafe in extraction targets, verify that each write path stays within the

Properties

ghsa_id
GHSA-f794-5jv7-7672
severity
medium
summary
NLTK: Downloader.download follows hardlinks and overwrites outside-root files
cvss_score
7.1
cve_id
CVE-2026-81727
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
is_ghsa_only
false
ghsa_published
2026-09-02T14:35:41Z
source_url
https://github.com/advisories/GHSA-f794-5jv7-7672
ghsa_updated
2026-09-02T14:35:42Z

Related Entities (6)

VULNERABLE_TO (1)

[Software]pip/nltk

AFFECTS (1)

[Software]pip/nltk

HAS_WEAKNESS (3)

[Weakness]External Control of File Name or Path
[Weakness]Improper Link Resolution Before File Access ('Link Following')
[Weakness]UNIX Symbolic Link (Symlink) Following

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81727 (CVSS 7.1) — Ninja Signal Threat Intelligence | Ninja Signal