在 NLTK 3.10.3 之前的版本中, 和 方法中存在一个文件系统包含(filesystem containment)绕过漏洞,允许攻击者通过预先存在的硬链接(hardlinks)覆盖安装根目录之外的文件。拥有共享下载器目录写权限的攻击者可以创建指向根目录外文件的硬链接,从而在正常的包解压过程中覆盖这些文件,导致预期安装目录树之外的文件被修改。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81722 | 7.5 HIGH | nltk PorterStemmer before 3.10.3 Quadratic-time DoS |
| CVE-2026-81726 | 7.0 HIGH | NLTK through 3.10.3 Path Traversal via Model-Artifact APIs |
| CVE-2026-81724 | 5.3 MEDIUM | NLTK before 3.10.3 Denial of Service via Uncontrolled Recursion |
| CVE-2026-81723 | 3.7 LOW | NLTK before 3.10.3 Quadratic CPU Exhaustion via XMLCorpusView |
| CVE-2026-81725 | 3.7 LOW | NLTK before 3.10.3 Regular Expression Denial of Service via Pl196xCorpusReader |
No comments yet