CVE-2026-81727
Severity CVSS v4.0:
MEDIUM
Type:
CWE-59
Link Following
Publication date:
27/08/2026
Last modified:
28/08/2026
Description
NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
7.10
Severity 3.x
HIGH



