CVE-2025-14009: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-14009 is a critical Zip Slip / code injection vulnerability in the NLTK (Natural Language Toolkit) downloader component, affecting all versions of nltk prior to 3.9.3. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without path validation, allowing attackers to craft malicious zip packages that, when extracted, can execute arbitrary code. It was published on February 18, 2026, and carries a CVSS v3.0 base score of 10.0 (Critical) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), manifesting as a Zip Slip vulnerability. The _unzip_iter function in nltk/downloader.py calls zipfile.extractall() without validating extracted file paths, meaning a crafted zip archive can write files to arbitrary locations on the filesystem — including placing malicious Python files (e.g., __init__.py) into importable package directories. Because NLTK implicitly trusts all downloaded packages, if a malicious package containing such Python files is extracted and subsequently imported, the embedded code executes automatically, achieving remote code execution with no authentication or user interaction required (Red Hat Bugzilla, Huntr PoC).

Impact

Successful exploitation results in full system compromise: an attacker can achieve arbitrary code execution in the context of the process running NLTK, enabling unauthorized file system read/write access, network access, credential theft, and the establishment of persistence mechanisms. The attack requires no privileges and no user interaction, and the changed scope indicator reflects that impact can extend beyond the vulnerable component itself to the broader host system (Red Hat Advisory, Red Hat Bugzilla). Multiple IBM products that bundle NLTK — including Watson Speech Services Cartridge, watsonx Orchestrate, IBM API Connect, QRadar Suite Software, and Instana Observability — are also affected (IBM Watson Advisory, IBM API Connect Advisory).

Exploitability

A public proof-of-concept exploit is available on Huntr, published around March 6, 2026 (Huntr PoC). As of the available intelligence, there is no confirmed evidence of active in-the-wild exploitation, and no threat actor attribution has been reported. The EPSS score is approximately 0.53%, and the vulnerability does not appear in the CISA KEV catalog at this time (Red Hat Advisory). The combination of a CVSS 10.0 score, no authentication requirement, and a public PoC makes this a high-priority patching target.

Exploitation steps

  1. Reconnaissance: Identify targets running NLTK (any version prior to 3.9.3) that use nltk.download() to fetch packages — common in NLP pipelines, data science environments, and AI/ML platforms.
  2. Craft malicious zip archive: Create a zip file containing path-traversal entries (e.g., ../../site-packages/some_package/__init__.py) with malicious Python code embedded in the file content.
  3. Host or intercept the package: Either compromise the NLTK data server, perform a man-in-the-middle attack on an unencrypted download, or distribute the malicious zip through a package mirror or supply chain attack vector.
  4. Trigger NLTK download: When the victim application calls nltk.download('target_package'), NLTK fetches and passes the zip to _unzip_iter, which calls zipfile.extractall() without path validation, writing the malicious __init__.py to an attacker-controlled path.
  5. Achieve code execution: Upon the next import of the affected package (which may happen automatically within the same NLTK session or on next application startup), the malicious Python code in __init__.py executes, granting the attacker arbitrary code execution (Huntr PoC, Red Hat Bugzilla).

Indicators of compromise

  • File System: Unexpected Python files (e.g., __init__.py) written outside the NLTK data directory (default: ~/nltk_data); files with path-traversal artifacts in zip extraction logs; new or modified files in Python site-packages directories with recent timestamps coinciding with NLTK download activity.
  • Network: Outbound connections from the NLTK host to unexpected IP addresses or domains following a package download event; NLTK download requests to non-official servers or unusual mirrors.
  • Logs: Application logs showing nltk.download() calls followed immediately by unexpected process spawning or import errors; Python interpreter logs showing execution of newly written __init__.py files from non-standard paths.
  • Process: Unusual child processes spawned by the Python interpreter running NLTK (e.g., bash, curl, wget, python -c); unexpected network connections initiated by the Python process after a package download.

Mitigation and workarounds

The primary remediation is to upgrade NLTK to version 3.9.3 or later, which introduces path validation in the zip extraction process (Red Hat Advisory). Organizations using affected IBM products (Watson Speech Services Cartridge, watsonx Orchestrate, API Connect, QRadar Suite, Instana Observability) should apply the respective IBM security bulletins (IBM Watson Advisory, IBM Instana Advisory). As a workaround where immediate patching is not possible, restrict network access for NLTK-using processes, pre-download all required NLTK packages from trusted sources in a controlled environment, and avoid calling nltk.download() in production systems exposed to untrusted networks.

Community reactions

The vulnerability received attention from security aggregators and NLP community members shortly after its February 18, 2026 disclosure, with coverage on The Hacker Wire and CyberHub Blog highlighting the CVSS 10.0 score (The Hacker Wire). Red Hat filed a high-severity bug report and IBM issued multiple security bulletins across its product portfolio, indicating broad downstream impact (Red Hat Bugzilla). Social media posts on Mastodon and Bluesky noted the critical severity and public PoC availability. Ubuntu also issued a security advisory (USN-8214-1) addressing the vulnerability in its packaged version of NLTK.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

nltk

Affected

sid

nltk: 3.9.3-1

Fixed

trixie

nltk

Affected

Ubuntu

Fixed

bionic (esm-apps)

nltk: 3.2.5-1ubuntu0.1+esm3

Fixed

devel

nltk

Affected

focal (esm-apps)

nltk: 3.4.5-2ubuntu0.1~esm3

Fixed

jammy

nltk

Affected

jammy (esm-apps)

nltk: 3.7-1ubuntu0.1~esm1

Fixed

noble

nltk

Affected

noble (esm-apps)

nltk: 3.8.1-1ubuntu0.1~esm1

Fixed

resolute

nltk

Affected

RHEL / CentOS

Unknown

Alpine

Fixed

edge

py3-nltk: 3.9.3-r0

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management