{"id":"CVE-2026-81727","title":"nltk: NLTK: Filesystem containment bypass allows local file overwrite (CVE-2026-81727)","summary":"A flaw was found in NLTK. This vulnerability, a filesystem containment bypass, allows a local attacker with write access to a shared downloader directory to create special links (hardlinks) that point to files outside the intended installa…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cvssSource":"vendor","cwe":["CWE-59","CWE-61","CWE-73"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","lightspeed_core","openshift_lightspeed","ansible_automation_platform 2","openshift_ai_rhoai","openshift_ai 3.5"],"patched":["openshift_ai 3.5"],"published":"2026-08-27","updated":"2026-09-22","sourceUpdated":"2026-09-22T05:58:56+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81727.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81727.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-81727"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2525096"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-81727"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81727"},{"url":"https://github.com/nltk/nltk/security/advisories/GHSA-f794-5jv7-7672"},{"url":"https://www.vulncheck.com/advisories/nltk-before-3.10.3-hardlink-file-overwrite-via-downloader"},{"url":"https://access.redhat.com/errata/RHSA-2026:69539"},{"url":"https://github.com/nltk/nltk/pull/3797"},{"url":"https://github.com/nltk/nltk/commit/9e6d5f05902b9aaa1221a0a565448d17a9c9b3e8"},{"url":"https://github.com/nltk/nltk/releases/tag/v3.10.3"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/nltk/PYSEC-2026-3741.yaml"},{"url":"https://github.com/advisories/GHSA-f794-5jv7-7672"}],"tags":["csaf","vex","red-hat","ghsa","pip"],"epss":0.00135,"epssPercentile":0.03346,"aliases":["GHSA-f794-5jv7-7672"],"ecosystem":"pip","ingestedAt":"2026-09-02T14:45:30.264Z","slug":"CVE-2026-81727","body":"## Overview\n\nA flaw was found in NLTK. This vulnerability, a filesystem containment bypass, allows a local attacker with write access to a shared downloader directory to create special links (hardlinks) that point to files outside the intended installation area. When a package is extracted, these hardlinks can cause files outside the NLTK installation to be overwritten, leading to unauthorized modification or corruption of data.\n\n## Vendor advisories\n\n- **RHSA-2026:69539** · Red Hat · fixed in: Red Hat OpenShift AI 3.5 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69539)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI) · no fix planned: Exploit Intelligence, Red Hat Ansible Automation Platform 2, Lightspeed Core, OpenShift Lightspeed, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81727.json)\n\n**nltk: NLTK: Filesystem containment bypass allows local file overwrite** — rated Important by Red Hat. Released 2026-08-27, updated 2026-09-22.\n\nAffected:\n\n- Exploit Intelligence\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat Ansible Automation Platform 2\n- Red Hat OpenShift AI (RHOAI)\n\nFixed:\n\n- Red Hat OpenShift AI 3.5\n\nNo fix planned:\n\n- Exploit Intelligence\n- Red Hat Ansible Automation Platform 2\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- Red Hat OpenShift AI 3.5\n- OpenShift Lightspeed\n\n## Remediation\n\nFor Red Hat OpenShift AI 3.5.1 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:69539\n\nWorkarounds / mitigations:\n\n- To mitigate this issue, ensure that NLTK downloader directories are not shared among untrusted users or are configured with restrictive permissions to prevent unauthorized write access. If a shared downloader directory is essential, implement strict access controls to limit write permissions to only trusted accounts. This reduces the attack surface by preventing malicious local users from creating hardlinks to arbitrary files.\n\n## Package advisory (CVE-2026-81727)\n\nAffected packages:\n\n- `nltk <= 3.10.2`\n\nPatched in:\n\n- `nltk 3.10.3`\n\nSource: https://github.com/advisories/GHSA-f794-5jv7-7672","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":202007,"id":"CVE-2026-81727","ts":1789400002187,"field":"severity","old":"medium","new":"high"},{"seq":200734,"id":"CVE-2026-81727","ts":1789397588131,"field":"severity","old":"high","new":"medium"},{"seq":199429,"id":"CVE-2026-81727","ts":1789395501942,"field":"severity","old":"medium","new":"high"},{"seq":198674,"id":"CVE-2026-81727","ts":1789392190536,"field":"severity","old":"high","new":"medium"},{"seq":197005,"id":"CVE-2026-81727","ts":1789384277280,"field":"severity","old":"medium","new":"high"},{"seq":196365,"id":"CVE-2026-81727","ts":1789383751698,"field":"severity","old":"high","new":"medium"},{"seq":195293,"id":"CVE-2026-81727","ts":1789380558939,"field":"severity","old":"medium","new":"high"},{"seq":194136,"id":"CVE-2026-81727","ts":1789378731415,"field":"severity","old":"high","new":"medium"},{"seq":192923,"id":"CVE-2026-81727","ts":1789376499824,"field":"severity","old":"medium","new":"high"},{"seq":191710,"id":"CVE-2026-81727","ts":1789373593190,"field":"severity","old":"high","new":"medium"},{"seq":190495,"id":"CVE-2026-81727","ts":1789369456547,"field":"severity","old":"medium","new":"high"},{"seq":189282,"id":"CVE-2026-81727","ts":1789368375742,"field":"severity","old":"high","new":"medium"},{"seq":188065,"id":"CVE-2026-81727","ts":1789365222648,"field":"severity","old":"medium","new":"high"},{"seq":186852,"id":"CVE-2026-81727","ts":1789363457171,"field":"severity","old":"high","new":"medium"},{"seq":185638,"id":"CVE-2026-81727","ts":1789361210112,"field":"severity","old":"medium","new":"high"},{"seq":184425,"id":"CVE-2026-81727","ts":1789358321242,"field":"severity","old":"high","new":"medium"},{"seq":182676,"id":"CVE-2026-81727","ts":1789354307948,"field":"severity","old":"medium","new":"high"},{"seq":181469,"id":"CVE-2026-81727","ts":1789353287564,"field":"severity","old":"high","new":"medium"},{"seq":180262,"id":"CVE-2026-81727","ts":1789350270392,"field":"severity","old":"medium","new":"high"},{"seq":179055,"id":"CVE-2026-81727","ts":1789348259357,"field":"severity","old":"high","new":"medium"},{"seq":177848,"id":"CVE-2026-81727","ts":1789346360695,"field":"severity","old":"medium","new":"high"},{"seq":176641,"id":"CVE-2026-81727","ts":1789343159579,"field":"severity","old":"high","new":"medium"},{"seq":174758,"id":"CVE-2026-81727","ts":1789334857667,"field":"severity","old":"medium","new":"high"},{"seq":173553,"id":"CVE-2026-81727","ts":1789333670504,"field":"severity","old":"high","new":"medium"},{"seq":172367,"id":"CVE-2026-81727","ts":1789331084710,"field":"severity","old":"medium","new":"high"},{"seq":171181,"id":"CVE-2026-81727","ts":1789328753104,"field":"severity","old":"high","new":"medium"},{"seq":169976,"id":"CVE-2026-81727","ts":1789327153518,"field":"severity","old":"medium","new":"high"},{"seq":168771,"id":"CVE-2026-81727","ts":1789323810068,"field":"severity","old":"high","new":"medium"},{"seq":167566,"id":"CVE-2026-81727","ts":1789319675125,"field":"severity","old":"medium","new":"high"},{"seq":166361,"id":"CVE-2026-81727","ts":1789318740880,"field":"severity","old":"high","new":"medium"},{"seq":165156,"id":"CVE-2026-81727","ts":1789315779337,"field":"severity","old":"medium","new":"high"},{"seq":163951,"id":"CVE-2026-81727","ts":1789313605478,"field":"severity","old":"high","new":"medium"},{"seq":162746,"id":"CVE-2026-81727","ts":1789311892039,"field":"severity","old":"medium","new":"high"},{"seq":161541,"id":"CVE-2026-81727","ts":1789308700822,"field":"severity","old":"high","new":"medium"},{"seq":159654,"id":"CVE-2026-81727","ts":1789300460318,"field":"severity","old":"medium","new":"high"},{"seq":156643,"id":"CVE-2026-81727","ts":1789294730734,"field":"severity","old":"high","new":"medium"},{"seq":155438,"id":"CVE-2026-81727","ts":1789292954455,"field":"severity","old":"medium","new":"high"},{"seq":154233,"id":"CVE-2026-81727","ts":1789289770736,"field":"severity","old":"high","new":"medium"},{"seq":153100,"id":"CVE-2026-81727","ts":1789285309908,"field":"severity","old":"medium","new":"high"},{"seq":152523,"id":"CVE-2026-81727","ts":1789281255330,"field":"severity","old":"high","new":"medium"},{"seq":151484,"id":"CVE-2026-81727","ts":1789277615152,"field":"severity","old":"medium","new":"high"},{"seq":150445,"id":"CVE-2026-81727","ts":1789276229867,"field":"severity","old":"high","new":"medium"},{"seq":149412,"id":"CVE-2026-81727","ts":1789273813527,"field":"severity","old":"medium","new":"high"},{"seq":148379,"id":"CVE-2026-81727","ts":1789271312137,"field":"severity","old":"high","new":"medium"},{"seq":147034,"id":"CVE-2026-81727","ts":1789269875711,"field":"severity","old":"medium","new":"high"},{"seq":145216,"id":"CVE-2026-81727","ts":1789266325262,"field":"severity","old":"high","new":"medium"},{"seq":144120,"id":"CVE-2026-81727","ts":1789262596344,"field":"severity","old":"medium","new":"high"},{"seq":143024,"id":"CVE-2026-81727","ts":1789261508961,"field":"severity","old":"high","new":"medium"},{"seq":141855,"id":"CVE-2026-81727","ts":1789258822137,"field":"severity","old":"medium","new":"high"},{"seq":140696,"id":"CVE-2026-81727","ts":1789256712972,"field":"severity","old":"high","new":"medium"}]}