Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-81727

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 3.4%
CVSS Severity
CVSS v3 Score 7.1


Contact Us

Shodan ® - All rights reserved