GHSA-gf32-cmjh-8m9vCriticalCVSS 7.1
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction...
🔗 CVE IDs covered (1)
📋 Description
NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS poisoning to inject malicious package contents that are extracted without validation.