NLTK versions before 3.10.3 contain a filesystem containment bypass vulnerability in the Downloader.download and Downloader.incr_download methods that allows attackers to overwrite files outside the install root through pre-existing hardlinks. Attackers with write access to a shared downloader directory can create hardlinks pointing to outside-root files that are then overwritten during normal package extraction, mutating files outside the intended install tree.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Nltk | Nltk | * | 3.10.3 (excluding) |
| Red Hat OpenShift AI 3.5 | RedHat | rhoai/odh-ta-lmes-job-rhel9:1788935863 | * |
| Nltk | Ubuntu | upstream | * |