Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-14751

26
FAUCET Score

CVE-2019-14751 is a directory traversal vulnerability in NLTK Downloader versions prior to 3.4.5, allowing attackers to write arbitrary files by embedding ".." in NLTK package ZIP archives during extraction. This vulnerability carries a CVSS score of 7.5 (High), indicating a low-complexity attack requiring no user interaction, with a high impact on integrity. While the EPSS score suggests a relatively low probability of exploitation, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.4.5CPE matchmatch criteria
cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
5.83%
Probability of exploitation in next 30 days
EPSS Percentile
92.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0583 is in the 87th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: nltkFixed in: 3.4.5

Vendor Advisories (1)

pipGHSA-mr7p-25v2-35wrhigh

NLTK Vulnerable To Path Traversal

Aug 23, 2019

References

lists.opensuse.org / opensuse-security-announce/2020-03/msg00054.html
lists.opensuse.org / opensuse-security-announce/2020-04/msg00001.html
github.com / mssalvatore/CVE-2019-14751_PoC
ExploitPatchThird Party Advisory
github.com / nltk/nltk/blob/3.4.5/ChangeLog
Release Notes
github.com / nltk/nltk/commit/f59d7ed8df2e0e957f7f247fe218032abdbe9a10
Patch
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QI4IJGLZQ5S7C5LNRNROHAO2P526XE3D
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ZGZSSEJH7RHH3RBUEVWWYT75QU67J7SE
salvatoresecurity.com / zip-slip-in-nltk-cve-2019-14751
ExploitPatchThird Party Advisory