
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14009 is a critical Zip Slip / code injection vulnerability in the NLTK (Natural Language Toolkit) downloader component, affecting all versions of nltk prior to 3.9.3. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without path validation, allowing attackers to craft malicious zip packages that, when extracted, can execute arbitrary code. It was published on February 18, 2026, and carries a CVSS v3.0 base score of 10.0 (Critical) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), manifesting as a Zip Slip vulnerability. The _unzip_iter function in nltk/downloader.py calls zipfile.extractall() without validating extracted file paths, meaning a crafted zip archive can write files to arbitrary locations on the filesystem — including placing malicious Python files (e.g., __init__.py) into importable package directories. Because NLTK implicitly trusts all downloaded packages, if a malicious package containing such Python files is extracted and subsequently imported, the embedded code executes automatically, achieving remote code execution with no authentication or user interaction required (Red Hat Bugzilla, Huntr PoC).
Successful exploitation results in full system compromise: an attacker can achieve arbitrary code execution in the context of the process running NLTK, enabling unauthorized file system read/write access, network access, credential theft, and the establishment of persistence mechanisms. The attack requires no privileges and no user interaction, and the changed scope indicator reflects that impact can extend beyond the vulnerable component itself to the broader host system (Red Hat Advisory, Red Hat Bugzilla). Multiple IBM products that bundle NLTK — including Watson Speech Services Cartridge, watsonx Orchestrate, IBM API Connect, QRadar Suite Software, and Instana Observability — are also affected (IBM Watson Advisory, IBM API Connect Advisory).
A public proof-of-concept exploit is available on Huntr, published around March 6, 2026 (Huntr PoC). As of the available intelligence, there is no confirmed evidence of active in-the-wild exploitation, and no threat actor attribution has been reported. The EPSS score is approximately 0.53%, and the vulnerability does not appear in the CISA KEV catalog at this time (Red Hat Advisory). The combination of a CVSS 10.0 score, no authentication requirement, and a public PoC makes this a high-priority patching target.
nltk.download() to fetch packages — common in NLP pipelines, data science environments, and AI/ML platforms.../../site-packages/some_package/__init__.py) with malicious Python code embedded in the file content.nltk.download('target_package'), NLTK fetches and passes the zip to _unzip_iter, which calls zipfile.extractall() without path validation, writing the malicious __init__.py to an attacker-controlled path.import of the affected package (which may happen automatically within the same NLTK session or on next application startup), the malicious Python code in __init__.py executes, granting the attacker arbitrary code execution (Huntr PoC, Red Hat Bugzilla).__init__.py) written outside the NLTK data directory (default: ~/nltk_data); files with path-traversal artifacts in zip extraction logs; new or modified files in Python site-packages directories with recent timestamps coinciding with NLTK download activity.nltk.download() calls followed immediately by unexpected process spawning or import errors; Python interpreter logs showing execution of newly written __init__.py files from non-standard paths.bash, curl, wget, python -c); unexpected network connections initiated by the Python process after a package download.The primary remediation is to upgrade NLTK to version 3.9.3 or later, which introduces path validation in the zip extraction process (Red Hat Advisory). Organizations using affected IBM products (Watson Speech Services Cartridge, watsonx Orchestrate, API Connect, QRadar Suite, Instana Observability) should apply the respective IBM security bulletins (IBM Watson Advisory, IBM Instana Advisory). As a workaround where immediate patching is not possible, restrict network access for NLTK-using processes, pre-download all required NLTK packages from trusted sources in a controlled environment, and avoid calling nltk.download() in production systems exposed to untrusted networks.
The vulnerability received attention from security aggregators and NLP community members shortly after its February 18, 2026 disclosure, with coverage on The Hacker Wire and CyberHub Blog highlighting the CVSS 10.0 score (The Hacker Wire). Red Hat filed a high-severity bug report and IBM issued multiple security bulletins across its product portfolio, indicating broad downstream impact (Red Hat Bugzilla). Social media posts on Mastodon and Bluesky noted the critical severity and public PoC availability. Ubuntu also issued a security advisory (USN-8214-1) addressing the vulnerability in its packaged version of NLTK.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
nltk: 3.2.5-1ubuntu0.1+esm3
devel
nltk
focal (esm-apps)
nltk: 3.4.5-2ubuntu0.1~esm3
jammy
nltk
jammy (esm-apps)
nltk: 3.7-1ubuntu0.1~esm1
noble
nltk
noble (esm-apps)
nltk: 3.8.1-1ubuntu0.1~esm1
resolute
nltk
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."