THREAT OPS › Threat News › [GHSA] GHSA-f794-5jv7-7672 (medium) — NLTK: Downloader.download follows hardlinks and overwrites outside-root files
[GHSA] GHSA-f794-5jv7-7672 (medium) — NLTK: Downloader.download follows hardlinks and overwrites outside-root files
GHSA-f794-5jv7-7672 Severity: medium CVE: CVE-2026-81727
NLTK: Downloader.download follows hardlinks and overwrites outside-root files
### Summary
NLTK's downloader now blocks symlink escapes during ZIP extraction, but it still treats pre-existing hardlinks inside the install tree as ordinary in-root files. A normal package install can therefore overwrite an outside-root inode through that hard
Indicators of compromise
- CVE-2026-81727cve
Original source: https://github.com/advisories/GHSA-f794-5jv7-7672