GHSA-4xw3-jf9x-x7mf
Dashboard / Vulnerabilities / GHSA-4xw3-jf9x-x7mf
GHSA-4xw3-jf9x-x7mf
Summary: Duplicate Advisory: Downloader.download follows hardlinks and overwrites outside-root files
Details: ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-f794-5jv7-7672. This link is maintained to preserve external references. ## Original Description NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.
References: https://github.com/nltk/nltk/security/advisories/GHSA-f794-5jv7-7672, https://nvd.nist.gov/vuln/detail/CVE-2026-81727, https://www.vulncheck.com/advisories/nltk-before-3.10.3-hardlink-file-overwrite-via-downloader
Affected packages
Package
Name: nltk
Purl: pkg:pypi/nltk
Affected ranges
Type: ECOSYSTEM
Events:
