CVE-2026-12261: A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `c...
Added to the CISA Known Exploited Vulnerabilities catalog on 07 Aug 2026. Vendor: AI/ML. Product: machine learning.
A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisoning. The downloader extracts package archives into shared namespaces such as `corpora/` and `taggers/` instead of package-isolated roots, and validates package integrity only afte...
Required action: Review and patch if applicable to your AI infrastructure.