THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f794-5jv7-7672 (medium) — NLTK: Downloader.download follows hardlinks and overwrites outside-root files

[GHSA] GHSA-f794-5jv7-7672 (medium) — NLTK: Downloader.download follows hardlinks and overwrites outside-root files

medgithub_advisoriesPublished 2026-09-02

GHSA-f794-5jv7-7672 Severity: medium CVE: CVE-2026-81727

NLTK: Downloader.download follows hardlinks and overwrites outside-root files

### Summary

NLTK's downloader now blocks symlink escapes during ZIP extraction, but it still treats pre-existing hardlinks inside the install tree as ordinary in-root files. A normal package install can therefore overwrite an outside-root inode through that hard

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f794-5jv7-7672