Количество 6
Количество 6
CVE-2026-81727
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.
CVE-2026-81727
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.
CVE-2026-81727
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.
CVE-2026-81727
NLTK versions before 3.10.3 contain a filesystem containment bypass vu ...
GHSA-f794-5jv7-7672
NLTK: Downloader.download follows hardlinks and overwrites outside-root files
BDU:2026-13263
Уязвимость компонентов nltk.downloader.Downloader.download и nltk.downloader.Downloader.incr_download пакета библиотек для символьной и статистической обработки естественного языка NLTK, позволяющая нарушителю обойти существующие механизмы безопасности и получить доступ на запись и удаление произвольных файлов
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-81727 NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree. | CVSS3: 7.1 | 0% Низкий | 20 дней назад | |
CVE-2026-81727 NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree. | CVSS3: 7.1 | 0% Низкий | 20 дней назад | |
CVE-2026-81727 NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree. | CVSS3: 7.1 | 0% Низкий | 20 дней назад | |
CVE-2026-81727 NLTK versions before 3.10.3 contain a filesystem containment bypass vu ... | CVSS3: 7.1 | 0% Низкий | 20 дней назад | |
GHSA-f794-5jv7-7672 NLTK: Downloader.download follows hardlinks and overwrites outside-root files | CVSS3: 7.1 | 0% Низкий | 14 дней назад | |
BDU:2026-13263 Уязвимость компонентов nltk.downloader.Downloader.download и nltk.downloader.Downloader.incr_download пакета библиотек для символьной и статистической обработки естественного языка NLTK, позволяющая нарушителю обойти существующие механизмы безопасности и получить доступ на запись и удаление произвольных файлов | CVSS3: 7.1 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу