Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-81727

Опубликовано: 27 авг. 2026
Источник: redhat
CVSS3: 7.1

Описание

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.

A flaw was found in NLTK. This vulnerability, a filesystem containment bypass, allows a local attacker with write access to a shared downloader directory to create special links (hardlinks) that point to files outside the intended installation area. When a package is extracted, these hardlinks can cause files outside the NLTK installation to be overwritten, leading to unauthorized modification or corruption of data.

Отчет

The NLTK library is vulnerable to a local file overwrite due to a filesystem containment bypass. An attacker with write access to a shared NLTK downloader directory can exploit this by creating hardlinks, leading to the overwriting of arbitrary files outside the intended installation path during package extraction. This could result in data integrity and availability impacts.

Меры по смягчению последствий

To mitigate this issue, ensure that NLTK downloader directories are not shared among untrusted users or are configured with restrictive permissions to prevent unauthorized write access. If a shared downloader directory is essential, implement strict access controls to limit write permissions to only trusted accounts. This reduces the attack surface by preventing malicious local users from creating hardlinks to arbitrary files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Affected
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Affected
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Affected
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Will not fix
Red Hat OpenShift AI (RHOAI)rhoai/odh-llama-stack-core-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-ogx-core-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2525096nltk: NLTK: Filesystem containment bypass allows local file overwrite

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
20 дней назад

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.

CVSS3: 7.1
nvd
20 дней назад

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.

CVSS3: 7.1
debian
20 дней назад

NLTK versions before 3.10.3 contain a filesystem containment bypass vu ...

CVSS3: 7.1
github
14 дней назад

NLTK: Downloader.download follows hardlinks and overwrites outside-root files

CVSS3: 7.1
fstec
около 1 месяца назад

Уязвимость компонентов nltk.downloader.Downloader.download и nltk.downloader.Downloader.incr_download пакета библиотек для символьной и статистической обработки естественного языка NLTK, позволяющая нарушителю обойти существующие механизмы безопасности и получить доступ на запись и удаление произвольных файлов

7.1 High

CVSS3