CVE-2026-59974: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in stanfordnlp stanza
Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes downloaded model and resource archives to zipfile.ZipFile.extractall without validating member paths, and the vulnerable extraction path is reachable through stanza.download and stanza.install_corenlp. A malicious archive containing parent-directory traversal entries can write outside the intended model directory, allowing files writable by the Stanza process to be overwritten and potentially enabling code execution through modified shell configuration, SSH authorization data, Python packages, or executable scripts. This issue is fixed in version 1.14.0.
AI Analysis
Technical Summary
The vulnerability in stanza (before 1.14.0) arises because stanza.resources.common.unzip uses zipfile.ZipFile.extractall without validating the paths of archive members. This allows a specially crafted archive containing parent-directory traversal entries to write files outside the intended extraction directory. The extraction functions reachable via stanza.download and stanza.install_corenlp are affected. Exploitation can overwrite files writable by the stanza process, potentially enabling code execution through altered shell configuration files, SSH authorization data, Python packages, or executable scripts. The vendor fixed this issue in stanza version 1.14.0.
Potential Impact
An attacker who can supply a malicious archive to stanza's download or install functions can overwrite arbitrary files writable by the stanza process. This can lead to high impact outcomes including code execution, data corruption, or privilege escalation depending on what files are overwritten. The CVSS 3.1 score is 7.8 (high), reflecting the local attack vector, low complexity, no privileges required, user interaction required, and high confidentiality, integrity, and availability impacts.
Mitigation Recommendations
Upgrade stanza to version 1.14.0 or later, where this path traversal vulnerability is fixed. Until then, avoid using stanza.download or stanza.install_corenlp with untrusted archives. There is no indication of alternative mitigations or temporary fixes.
CVE-2026-59974: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in stanfordnlp stanza
Description
Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes downloaded model and resource archives to zipfile.ZipFile.extractall without validating member paths, and the vulnerable extraction path is reachable through stanza.download and stanza.install_corenlp. A malicious archive containing parent-directory traversal entries can write outside the intended model directory, allowing files writable by the Stanza process to be overwritten and potentially enabling code execution through modified shell configuration, SSH authorization data, Python packages, or executable scripts. This issue is fixed in version 1.14.0.
CVSS v3.1
Score 7.8high
Affected software
stanfordnlp
stanza
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in stanza (before 1.14.0) arises because stanza.resources.common.unzip uses zipfile.ZipFile.extractall without validating the paths of archive members. This allows a specially crafted archive containing parent-directory traversal entries to write files outside the intended extraction directory. The extraction functions reachable via stanza.download and stanza.install_corenlp are affected. Exploitation can overwrite files writable by the stanza process, potentially enabling code execution through altered shell configuration files, SSH authorization data, Python packages, or executable scripts. The vendor fixed this issue in stanza version 1.14.0.
Potential Impact
An attacker who can supply a malicious archive to stanza's download or install functions can overwrite arbitrary files writable by the stanza process. This can lead to high impact outcomes including code execution, data corruption, or privilege escalation depending on what files are overwritten. The CVSS 3.1 score is 7.8 (high), reflecting the local attack vector, low complexity, no privileges required, user interaction required, and high confidentiality, integrity, and availability impacts.
Mitigation Recommendations
Upgrade stanza to version 1.14.0 or later, where this path traversal vulnerability is fixed. Until then, avoid using stanza.download or stanza.install_corenlp with untrusted archives. There is no indication of alternative mitigations or temporary fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-07T19:41:00.004Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aaac11a55bf5e2cf5d8dce8
Added to database: 09/16/2026, 16:17:30 UTC
Last enriched: 09/16/2026, 16:31:51 UTC
Last updated: 09/16/2026, 22:11:10 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.