OSV 1.4.0 · github-reviewed · 修改于 2026-09-02 04:30
发布时间
2026-08-03 17:32
GitHub 审查时间
2026-09-02 04:30
NVD 发布时间
2026-08-03 16:17
源文件
advisories/github-reviewed/2026/08/GHSA-pv39-qrfq-g8gc/GHSA-pv39-qrfq-g8gc.json
该公告已于 2026-09-02 04:30 撤回
内容仅用于保留外部引用,请不要将其当作仍然有效的安全结论。
This advisory has been withdrawn because it is a duplicate of GHSA-5wp5-5229-5g6q. This link is maintained to preserve external references.
In nltk version 3.9.4, the nltk.downloader.Downloader._download_package() function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This allows an attacker to tamper with the package response body for info.url through a compromised mirror, malicious proxy, or other source-substitution condition, leading to the installation of attacker-controlled package bytes. The vulnerability can result in malicious corpus or model content being trusted by downstream users or applications.