CVE-2026-33236 affects NLTK (Natural Language Toolkit) versions 3.9.3 and prior, stemming from a lack of validation in its downloader when processing remote XML index files. This high-severity vulnerability (CVSS 8.1) allows unauthenticated remote attackers to achieve arbitrary file and directory creation or overwrite through path traversal sequences, requiring user interaction. Attackers can exploit this by controlling a remote XML index server to provide malicious values. While there is no known active exploitation, public exploit code, or CISA KEV listing, a patch is available in commit 89fe2ec2c6bae6e2e7a46dad65cc34231976ed8a.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.9.3CPE matchmatch criteria | cpe:2.3:a:nltk:nltk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
NLTK vulnerabilities
May 25, 2026NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
Mar 19, 2026NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
Mar 19, 2026NLTK has a Downloader Path Traversal Vulnerability (AFO) - Arbitrary File Overwrite
Mar 19, 2026