FixVibe

// 코드 / 스포트라이트

NLTK Zip Slip Code Execution Advisory

A vulnerable NLTK downloader can turn compromised package archives into filesystem writes and code-execution risk.

What it is

NLTK data downloads often run during bootstrap, notebooks, CI, model preparation, or worker startup. A vulnerable downloader matters wherever those paths can pull a malicious or compromised data package.

How it happens

CVE-2025-14009 is a Zip Slip in NLTK's data downloader, fixed in NLTK 3.9.3. When the downloader extracts a package archive, entries with crafted paths can be written outside the NLTK data directory, including into places Python later imports code from.

What an attacker gets

If an affected NLTK release downloads and extracts a malicious or compromised data package, files can land outside the intended directory and later run as code in your worker, notebook, or CI job, with whatever credentials that process holds.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade `nltk` to 3.9.3 or newer, regenerate the active Python lockfile, and rebuild every runtime, CI job, worker, notebook, or image that can call NLTK downloader code. Review `nltk.download()` and custom NLTK data mirror/cache usage so package sources stay trusted, then verify with dependency-tree and benign application tests.

// 내 앱에서 직접 실행해보세요

FixVibe가 지켜보는 동안 계속 배포하세요.

Connect a GitHub repo to check its code, dependencies and workflows.

소스 코드
198
이 카테고리에서 실행되는 테스트
모듈
155
전용 소스 코드 검사
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// 최신 체크 · 실용적인 수정 · 자신 있게 배포

NLTK Zip Slip Code Execution Advisory: what it is and how to fix it · FixVibe