Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-14009

39
FAUCET Score

CVE-2025-14009 is a critical remote code execution vulnerability in the NLTK downloader component (nltk/nltk) affecting all versions. This flaw, rated CVSS 10.0, allows unauthenticated attackers to execute arbitrary code by crafting malicious zip packages that exploit NLTK's lack of path validation during extraction. The vulnerability enables full system compromise, including file system and network access, due to automatic execution of malicious Python files upon import. While there are no known public exploits or active exploitation, the vulnerability has garnered some community discussion, indicating potential future interest.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.9.3CPE matchmatch criteria
cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

10.0CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.79%
Probability of exploitation in next 30 days
EPSS Percentile
52.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0079 is in the 46th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

pippatch availablevia ghsa
Product: nltkFixed in: 3.9.3
redhatno patchvia redhat_api
Product: OpenShift LightspeedFixed in: openshift-lightspeed/lightspeed-ocp-rag-rhel9
redhatno patchvia redhat_api
Product: OpenShift LightspeedFixed in: openshift-lightspeed/lightspeed-service-api-rhel9
redhatno patchvia redhat_api
Product: OpenShift LightspeedFixed in: openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9
redhatno patchvia redhat_api
Product: Lightspeed CoreFixed in: lightspeed-core/lightspeed-stack-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-ta-lmes-job-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-llama-stack-core-rhel9

Vendor Advisories (2)

pipGHSA-7p94-766c-hgjpcritical

NLTK has a Zip Slip Vulnerability

Feb 18, 2026
redhatCVE-2025-14009Important

nltk: Zip Slip Vulnerability in nltk Leading to Code Execution

Feb 18, 2026

References

access.redhat.com / errata/RHSA-2026:10184
access.redhat.com / security/cve/CVE-2025-14009
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2025/cve-2025-14009.json
huntr.com / bounties/49ecbc02-054e-4470-b2e0-b267936cc4e4
ExploitThird Party Advisory