CVE-2025-14009 is a critical remote code execution vulnerability in the NLTK downloader component (nltk/nltk) affecting all versions. This flaw, rated CVSS 10.0, allows unauthenticated attackers to execute arbitrary code by crafting malicious zip packages that exploit NLTK's lack of path validation during extraction. The vulnerability enables full system compromise, including file system and network access, due to automatic execution of malicious Python files upon import. While there are no known public exploits or active exploitation, the vulnerability has garnered some community discussion, indicating potential future interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.9.3CPE matchmatch criteria | cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.