CVE-2026-12261
Last modified
CVE-2026-12261 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of package-isolated roots, and validates package integrity only after the archive has been written and extracted. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of package-isolated roots, and validates package integrity only after the archive has been written and extracted. This design flaw enables one package to overwrite another package's trusted resources within the same namespace, making the changes immediately active through ordinary NLTK APIs. This issue persists across fresh interpreter restarts and can affect downstream workflows, including machine learning pipelines and reproducibility-sensitive environments.
Metrics
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| nltk | nltk/nltk | <= latest |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-12261?
How severe is CVE-2026-12261?
How do I fix CVE-2026-12261?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12252In nltk/nltk versions 3.9.3 and earlier, five Stanford inter…7.8
- CVE-2026-12255The MainWP Child WordPress plugin before 6.1.2 does not ver…8.1
- CVE-2026-12256Contributor PHP Object Injection in Avada <= 3.15.3 versions…8.8
- CVE-2026-12257Versions of Mura CMS prior to 10.0.712 contain a critical re…9.3
- CVE-2026-12259In nltk version 3.9.4, the `nltk.downloader.Downloader._down…5.3
- CVE-2026-1226CWE‑94: Improper Control of Generation of Code vulnerability…7
- CVE-2026-1227CWE-611: Improper Restriction of XML External Entity Referen…7
- CVE-2026-12270The Everest Forms WordPress plugin before 3.5.0 does not co…6.5
- CVE-2026-12271The Tutor LMS WordPress plugin before 3.9.13 does not verif…5.4
- CVE-2026-12273The Tutor LMS WordPress plugin before 3.9.13 does not perfo…4.3
- CVE-2026-12274The Tutor LMS WordPress plugin before 3.9.13 does not verif…6.5
- CVE-2026-12275The Tutor LMS WordPress plugin before 3.9.13 does not, in i…7.1
Are you affected by CVE-2026-12261?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
