Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-12261— Improper Access Control in nltk/nltk

Quick assessment

Affected
nltk nltk/nltk
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

nltk/nltk 3.9.4 及以下版本中的 存在一个漏洞,可能导致跨包的资源与模型投毒。该下载器将包存档提取至共享命名空间(如 和 ),而非各包隔离的根目录;并且仅在存档写入并提取完成后才验证包的完整性。这一设计缺陷使得一个包可以覆盖同一命名空间中另一个包的受信任资源,从而通过常规的 NLTK API 立即生效。此问题在解释器全新重启后仍然存在,并可能影响下游工作流程,包括机器学习管线和可重复性敏感的环境。

AI Predicted 7.5 Difficulty: Moderate EPSS 0.21% · P9

Affected Version Matrix 1

VendorProduct Version RangeStatus
nltk nltk/nltk unspecified≤ latest affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12261

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper Access Control in nltk/nltk
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of package-isolated roots, and validates package integrity only after the archive has been written and extracted. This design flaw enables one package to overwrite another package's trusted resources within the same namespace, making the changes immediately active through ordinary NLTK APIs. This issue persists across fresh interpreter restarts and can affect downstream workflows, including machine learning pipelines and reproducibility-sensitive environments.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nltk nltk/nltk unspecified ~ latest -

II. Public POCs for CVE-2026-12261

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12261

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-12261 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-12261

No comments yet


Leave a comment