Executive brief
The Natural Language Toolkit (NLTK), a popular Python library for processing human language data, contains a security flaw in its data downloader component. If a user is tricked into downloading data from a malicious server, an attacker can create or overwrite files anywhere on the user's computer. This could lead to a total system compromise if critical system files or security keys are replaced by the attacker.
Technical details
A path traversal vulnerability exists in the NLTK downloader (nltk/downloader.py) due to insufficient validation of the 'subdir' and 'id' attributes within remote XML index files. An attacker who controls a remote XML index server can provide malicious values containing sequences like '../'. When a victim uses the downloader to fetch a package from this malicious source, the library uses these unvalidated strings to construct file paths via os.path.join(). This allows the attacker to escape the intended download directory and perform arbitrary file creation or overwriting (AFO) on the local filesystem. The issue is patched in commit 89fe2ec2c6bae6e2e7a46dad65cc34231976ed8a.
Affected products
- nltk nltk <= 3.9.3
- Red Hat Red Hat OpenShift AI 2.25
- Red Hat Red Hat OpenShift AI 3.3
- Red Hat Lightspeed Core
- Red Hat OpenShift Lightspeed
- Red Hat Red Hat Ansible Automation Platform 2
Timeline
- 2026-03-18: advisory: GitHub Security Advisory published
- 2026-03-20: disclosed: NVD publication date
- 2026-04-23: patched: Red Hat released security updates for OpenShift AI
References
- https://github.com/nltk/nltk/commit/89fe2ec2c6bae6e2e7a46dad65cc34231976ed8a
- https://github.com/nltk/nltk/security/advisories/GHSA-469j-vmhf-r6v7
- https://access.redhat.com/errata/RHSA-2026:10184
- https://access.redhat.com/errata/RHSA-2026:19712
- https://access.redhat.com/security/cve/CVE-2026-33236
- https://bugzilla.redhat.com/show_bug.cgi?id=2449824
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33236.json