Sami Laiho[verified]@samilaihoDisclosure
CVE-2025-14009 is a critical Zip Slip vulnerability in nltk that allows remote code execution; an official fix is available and a proof‑of‑concept exists.
ThreatCluster[verified]@threatclusterPatch
The advisory discloses a critical NLTK CVE causing arbitrary code execution through malicious zip files and urges users to apply the available patch immediately.
DailyCVE@dailycveDisclosure
The brief excerpt references a critical code‑injection vulnerability in NLTK (CVE‑2025‑14009) but provides only minimal technical detail and no evidence of PoCs, exploits, or mitigations.
PulsePatch.io@pulsepatchioPatch
The tweet announces a path traversal vulnerability (CVE‑2025‑14009) in NLTK’s downloader that allows arbitrary file writes via crafted zip archives, and points to a mitigation resource on PulsePatch.
PulsePatch.io@pulsepatchioDisclosure
The post announces a path‑traversal flaw (CVE‑2025‑14009) in NLTK's downloader that permits arbitrary file writes, urging caution with untrusted data. No PoC, exploit, active use, patch, or false‑positive claim are provided.
CVE@CVEnewDisclosure
The text announces a critical CVE in NLTK’s downloader component but provides no technical details, PoC, exploit code, or patch information.
The Hacker Wire@TheHackerWireDisclosure
The post announces a critical vulnerability (CVE‑2025‑14009) in NLTK’s downloader component, mentioning a flaw in zipfile extraction, but offers no PoC, exploit, patch, or active exploitation details.