Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-81727

Опубликовано: 27 авг. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.1

Описание

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.

РелизСтатусПримечание
devel

not-affected

3.10.3-1
esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

esm-infra-legacy/trusty

needs-triage

jammy

needs-triage

noble

needs-triage

Показывать по

EPSS

Процентиль: 3%
0.00135
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
redhat
20 дней назад

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.

CVSS3: 7.1
nvd
20 дней назад

NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.

CVSS3: 7.1
debian
20 дней назад

NLTK versions before 3.10.3 contain a filesystem containment bypass vu ...

CVSS3: 7.1
github
14 дней назад

NLTK: Downloader.download follows hardlinks and overwrites outside-root files

CVSS3: 7.1
fstec
около 1 месяца назад

Уязвимость компонентов nltk.downloader.Downloader.download и nltk.downloader.Downloader.incr_download пакета библиотек для символьной и статистической обработки естественного языка NLTK, позволяющая нарушителю обойти существующие механизмы безопасности и получить доступ на запись и удаление произвольных файлов

EPSS

Процентиль: 3%
0.00135
Низкий

7.1 High

CVSS3