CVE-2025-14009Disclosure(nltk / nltk)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch nltk nltk systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This allows attackers to craft malicious zip packages that, when downloaded and extracted by NLTK, can execute arbitrary code. The vulnerability arises because NLTK assumes all downloaded packages are trusted and extracts them without validation. If a malicious package contains Python files, such as __init__.py, these files are executed automatically upon import, leading to remote code execution. This issue can result in full system compromise, including file system access, network access, and potential persistence mechanisms.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nltk

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 4d ago at 2 mentions (2026-02-18); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
nltk

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-02-18: 2Mentions · 2026-02-19: 1Mentions · 2026-02-20: 2Mentions · 2026-03-07: 1Mentions · 2026-04-28: 1PoC Mentioned / Linked · 2026-02-19: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 2Technical Details · 2026-03-07: 1Technical Details · 2026-04-28: 102-1802-1902-2003-0704-28
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-182
Disclosure2
2026-02-191
Disclosure1
2026-02-202
Disclosure1Patch1
2026-03-071
Disclosure1
2026-04-281
Patch1
Full discourse7 posts
  • Sami Laiho@samilaiho
    Disclosure

    Zip Slip Vulnerability in nltk/nltk Leading to Remote Code Execution URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14009 Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv3.1: 10.0

    Post summary

    CVE-2025-14009 is a critical Zip Slip vulnerability in nltk that allows remote code execution; an official fix is available and a proof‑of‑concept exists.

    01031509
    30.4K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical NLTK bug CVE-2025-14009 in Ubuntu 14.04-24.04 allows arbitrary code execution via malicious zip files, users urged to update packages immediately. https://threatcluster.io/cluster/critical-nltk-vulnerability-in-multiple-ubuntu-releases-73eaaded

    Post summary

    The advisory discloses a critical NLTK CVE causing arbitrary code execution through malicious zip files and urges users to apply the available patch immediately.

    00000635
    166 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 NLTK, Code Injection, #CVE-2025-14009 (Critical) https://dailycve.com/nltk-code-injection-cve-2025-14009-critical/

    Post summary

    The brief excerpt references a critical code‑injection vulnerability in NLTK (CVE‑2025‑14009) but provides only minimal technical detail and no evidence of PoCs, exploits, or mitigations.

    00000135
    166 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `NLTK` is vulnerable to a path traversal flaw (CVE-2025-14009) in its downloader, enabling arbitrary file writes via crafted zip archives. Mitigation details: #nltk #infosec #pathtraversal https://www.pulsepatch.io/posts/cve-2025-14009-nltk-path-traversal

    Post summary

    The tweet announces a path traversal vulnerability (CVE‑2025‑14009) in NLTK’s downloader that allows arbitrary file writes via crafted zip archives, and points to a mitigation resource on PulsePatch.

    0000037
    1 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A path traversal vulnerability (CVE-2025-14009) affects the `NLTK` downloader, allowing arbitrary file writes. Evaluate `nltk` use with untrusted data. #Python #PathTraversal #infosec https://www.pulsepatch.io/posts/ubuntu-cve-2025-14009-nltk-path-traversal-vulnerability

    Post summary

    The post announces a path‑traversal flaw (CVE‑2025‑14009) in NLTK's downloader that permits arbitrary file writes, urging caution with untrusted data. No PoC, exploit, active use, patch, or false‑positive claim are provided.

    0000041
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-14009 A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.ext… https://www.cve.org/CVERecord?id=CVE-2025-14009

    Post summary

    The text announces a critical CVE in NLTK’s downloader component but provides no technical details, PoC, exploit code, or patch information.

    00000149
    56.4K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-14009 - Critical A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without per... https://www.thehackerwire.com/vulnerability/CVE-2025-14009/ https://t.co/wUKtQpU050

    Post summary

    The post announces a critical vulnerability (CVE‑2025‑14009) in NLTK’s downloader component, mentioning a flaw in zipfile extraction, but offers no PoC, exploit, patch, or active exploitation details.

    0000052
    112 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnltknltk---

Explore more