Security: copier-org/copier
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
The 9.17.0 trust fix introduced a new bypass: an encoded separator plus a literal `../` escapes a trusted URL prefix, so an untrusted template runs its tasks unpromptedGHSA-v846-q23v-m9gj published
Sep 7, 2026 by sispHigh -
Percent-encoded '..' in gl: (GitLab) shortcut template URLs bypasses the trust check, running tasks unpromptedGHSA-32vq-99v3-4gf7 published
Sep 1, 2026 by sispHigh -
Copier safe-template symlink escape during Jinja includeGHSA-rg63-g45r-jc58 published
Aug 19, 2026 by sispModerate -
Copier safe template has arbitrary filesystem read access via .. path traversal in !include tagGHSA-p86q-xwwq-6c64 published
Aug 19, 2026 by sispModerate -
Safe template executes arbitrary code via YAML tagsGHSA-v9wr-3fjh-hg69 published
Aug 4, 2026 by sispHigh -
Safe template executes arbitrary code via Jinja sandbox escape through path and settings objectsGHSA-7537-j7hq-f8p9 published
Aug 4, 2026 by sispHigh -
Percent-encoded path traversal segments in template URLs can allow trusted-prefix escapeGHSA-34mv-rjq9-5mch published
Jul 15, 2026 by sispHigh -
Copier: trust-prefix bypass via path traversal runs tasks unpromptedGHSA-9gmc-jqmh-3rvm published
Jun 13, 2026 by sispHigh -
Copier `_subdirectory` allows template root escape via parent-directory traversalGHSA-85v3-4m8g-hrh6 published
Mar 31, 2026 by sispModerate -
Copier `_external_data` allows path traversal and absolute-path local file read without unsafe modeGHSA-hgjq-p8cr-gg4h published
Mar 31, 2026 by sispModerate
Learn more about advisories related to copier-org/copier in the GitHub Advisory Database