What is CVE-2026-12261?
This vulnerability exists in the `nltk.downloader` function of NLTK library (version ≤ 3.9.4) and allows for cross-package resource and model poisoning. As archives are extracted into shared namespaces like `corpora/` and `taggers/`, a malicious package can overwrite or corrupt other resources. It is recommended to update affected versions to the latest secure release.
Azərbaycanca: Bu boşluq NLTK kitabxanasının `nltk.downloader` funksiyasında aşkar edilib (versiya ≤ 3.9.4) və cross-package resource/model poisoning hücumuna imkan verir. Arxivlər ümumi `corpora/` və `taggers/` kimi qovluqlara çıxarıldığı üçün zərərli paket digər resursları yoluxdura bilir. Təsirlənən versiyaları ən son təhlükəsiz versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which function in the NLTK library contains the CVE-2026-12261 vulnerability?
This vulnerability exists in the `nltk.downloader` function of the NLTK library.
How does CVE-2026-12261 allow a malicious package to infect other resources?
Since archives are extracted into shared namespaces like `corpora/` and `taggers/`, a malicious package can overwrite or corrupt other resources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.