CVE-2026-62999
- EPSS 0.29%
- Veröffentlicht 31.07.2026 19:41:55
- Zuletzt bearbeitet 31.07.2026 20:16:53
Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP server ...
CVE-2026-53951
- EPSS 0.19%
- Veröffentlicht 08.07.2026 15:26:08
- Zuletzt bearbeitet 10.07.2026 19:06:45
Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's prefix match (`copier/_settings.py`) compares the template URL against a trusted prefix with a raw `str.startswith` and no path n...
CVE-2026-34730
- EPSS 0.29%
- Veröffentlicht 02.04.2026 18:09:16
- Zuletzt bearbeitet 24.07.2026 21:10:00
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template ...
CVE-2026-34726
- EPSS 0.38%
- Veröffentlicht 02.04.2026 18:07:35
- Zuletzt bearbeitet 24.07.2026 21:10:00
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory trave...
CVE-2026-23986
- EPSS 0.23%
- Veröffentlicht 21.01.2026 22:20:37
- Zuletzt bearbeitet 02.02.2026 14:10:51
Copier is a library and CLI app for rendering project templates. Prior to version 9.11.2, Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would re...
CVE-2026-23968
- EPSS 0.2%
- Veröffentlicht 21.01.2026 22:13:25
- Zuletzt bearbeitet 02.02.2026 14:11:03
Copier is a library and CLI app for rendering project templates. Prior to version 9.11.2, Copier suggests that it's safe to generate a project from a safe template, i.e. one that doesn't use unsafe features like custom Jinja extensions which would re...