Vulnerability GHSA-ffj6-66c4-86gw

Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 month ago
August 07, 2026 at 09:31 AM UTC
NLTK downloader allows cross-package resource and model poisoning
0.8 - 0.9.9 and 2.0b4 - 3.9.4
0.8 - 0.9.9 and 2.0b4 - 3.9.4

Summary

NLTK downloader allows cross-package resource and model poisoning

Details

A vulnerability in nltk.downloader in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as corpora/ and taggers/ instead of package-isolated roots, and validates package integrity only after the archive has been written and extracted. This design flaw enables one package to overwrite another package's trusted resources within the same namespace, making the changes immediately active through ordinary NLTK APIs. This issue persists across fresh interpreter restarts and can affect downstream workflows, including machine learning pipelines and reproducibility-sensitive environments.

Impacted packages

Timeline

Published
1 month ago
August 07, 2026 at 09:31 AM UTC
Fixed (3.10.0)
2 months ago
July 08, 2026 at 02:39 AM UTC
Last Modified
9 hours ago
October 02, 2026 at 11:30 PM UTC