copier
Library and command-line utility for rendering projects templates.
Activity
- Latest release
- 1w ago
- Total releases
- 95
- Cadence
- ~19 days
- Last 12 months
- 22
Reach
- Stars
- 3.6k
Details
- License
- MIT
- First release
- Feb 07, 2019
| Version | Released | |
|---|---|---|
9.18.2
patch
| ||
9.18.1
patch
| ||
9.18.0
minor
| ||
9.17.2
patch
| ||
9.17.1
patch
| ||
9.17.0
minor
| ||
9.16.0
minor
| ||
9.15.2
patch
| ||
9.15.1
patch
1 CVE
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
9.15.0
minor
1 CVE
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
9.14.3
patch
1 CVE
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
9.14.2
patch
1 CVE
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
9.14.1
patch
1 CVE
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
9.14.0
minor
3 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.13.1
patch
3 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.13.0
minor
3 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.12.0
minor
3 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.11.3
patch
3 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.11.2
patch
3 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.11.1
patch
5 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.11.0
minor
5 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.10.3
patch
5 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.10.2
patch
5 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.10.1
patch
5 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.10.0
minor
5 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.9.1
patch
5 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.9.0
minor
7 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.8.0
minor
7 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.7.1
patch
7 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.7.0
minor
7 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.6.0
minor
7 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.5.0
minor
7 CVEs
CVE-2026-53951
PYSEC-2026-3818
GHSA-9gmc-jqmh-3rvm
Sep 10, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Critical
Local
Low
None
Copier: trust-prefix bypass via path traversal runs tasks unpromptedSummaryIn copier Details
This decision gates code execution —
The chain: the trust comparison sees the raw URL, so
This is most acute on In-repo asymmetry that confirms the omission: copier consistently resolves
paths everywhere else it makes a security decision — PoCSelf-contained standalone script; runs against a clean, pinned PyPI install via
the real Build and run:
Observed output (
The exploit is the same template as the control plus the minimal delta
ImpactA user who has configured a trusted prefix (a trailing- Proposed severity: High, comparable to the project's prior unsafe-template
advisory (GHSA-3xw7-v6cj-5q8h). Proposed CVSS v4 vector (maintainer to finalize;
Recommended fixNormalize both sides before comparing, instead of raw References
Affected versions
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
+ 12 more Show less
9.14.1
9.14.2
9.14.3
9.15.0
9.15.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.15.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.4.1
patch
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.4.0
minor
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.3.1
patch
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.3.0
minor
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.2.0
minor
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.1
patch
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.1.0
minor
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
9.0.1
major
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
8.3.0
minor
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
8.2.0
minor
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
8.1.0
minor
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
8.0.0
major
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
7.2.0
minor
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
7.1.0
minor
6 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55214
PYSEC-2026-1273
GHSA-p7q8-grrj-3m8w
Jul 07, 2026
Copier's safe template has filesystem write access outside destination path
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Write access via generated relative pathReproducible example:
Write access via generated absolute pathReproducible example:
This scenario is slightly less severe, as Copier has a few assertions of the destination path being relative which would typically be raised. But Affected versions
7.1.0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
+ 8 more Show less
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
7.1.0a0
pre
5 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev | ||
7.0.1
major
5 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev |
7.0.1
major
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
6.2.0
minor
5 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev |
6.2.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
6.1.0
minor
5 CVEs
CVE-2026-23986
PYSEC-2026-1272
GHSA-4fqp-r85r-hxqh
Jul 07, 2026
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Critical
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the
Reproducible example (may or may not work depending on directory entry yield order):
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-23968
PYSEC-2026-1274
GHSA-xjhm-gp88-8pfx
Jul 07, 2026
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
High
Local
Low
None
ImpactCopier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Imagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Patchesn/a Workaroundsn/a Referencesn/a Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 64 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.11.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-55201
PYSEC-2026-1271
GHSA-3xw7-v6cj-5q8h
Jul 07, 2026
Copier's safe template has arbitrary filesystem read/write access
Critical
Local
Low
None
ImpactCopier's current security model shall restrict filesystem access through Jinja:
Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would require passing the Arbitrary read accessImagine, e.g., a malicious template author who creates a template that reads SSH keys or other secrets from well-known locations, perhaps "masks" them with Base64 encoding to reduce detection risk, and hopes for a user to push the generated project to a public location like github.com where the template author can extract the secrets. Reproducible example:
Arbitrary write accessImagine, e.g., a malicious template author who creates a template that overwrites or even deletes files to cause havoc. Reproducible examples:
Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 57 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
Fixed in
9.9.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-34730
PYSEC-2026-2135
GHSA-hgjq-p8cr-gg4h
Apr 02, 2026
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
High
None
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34726
PYSEC-2026-2134
GHSA-85v3-4m8g-hrh6
Apr 02, 2026
4.4
/ 10
Medium
Local
Low
None
Required
Unchanged
Low
Low
None
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Affected versions
2.0.0
2.0.1
2.1.0
2.2.1
2.2.2
2.2.3
2.3
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
+ 70 more Show less
2.4.2
2.5.0
2.5.1
3.0.0a3
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0b1
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.2.0
4.0.0
4.0.1
4.0.2
4.1.0
5.0.0
5.1.0
6.0.0
6.0.0a0
6.0.0a2
6.0.0a3
6.0.0a4
6.0.0a5
6.0.0a6
6.0.0a7
6.0.0a9
6.0.0b0
6.1.0
6.2.0
7.0.1
7.1.0
7.1.0a0
7.2.0
8.0.0
8.1.0
8.2.0
8.3.0
9.0.1
9.1.0
9.1.1
9.10.0
9.10.1
9.10.2
9.10.3
9.11.0
9.11.1
9.11.2
9.11.3
9.12.0
9.13.0
9.13.1
9.14.0
9.2.0
9.3.0
9.3.1
9.4.0
9.4.1
9.5.0
9.6.0
9.7.0
9.7.1
9.8.0
9.9.0
9.9.1
Fixed in
9.14.1
References Updated Jul 13, 2026 · Source: OSV.dev |
6.1.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|