


Perceptive Security
SOC/SIEM Consultancy

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators…
Published:
31 July 2026 at 00:00:00
Alert date:
31 July 2026 at 23:02:18
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
A security vulnerability exists in Copier, a library and CLI app for rendering project templates, affecting versions 9.5.0 through 9.16.0. The flaw allows percent-encoded parent-directory segments or encoded path separators in a template URL to match a configured trusted repository prefix before the HTTP server or Git transport decodes the path. This path confusion enables unsafe template features from an untrusted repository outside the configured trusted prefix to execute after user interaction. The vulnerability is classified as a trust bypass via URL encoding/path traversal techniques. No exploitation in the wild has been mentioned, but the risk is significant given the potential for arbitrary code execution through malicious templates. The issue has been patched in version 9.17.0 of Copier. Users are advised to upgrade immediately to the fixed release. The fix is documented in a GitHub security advisory (GHSA-34mv-rjq9-5mch) and a corresponding commit.
Technical details
Mitigation steps:
Affected products:
Copier 9.5.0-9.16.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-62999
https://github.com/copier-org/copier/commit/7408f0d6287a7bf452715fd9f25dc54eaba3c295
https://github.com/copier-org/copier/releases/tag/v9.17.0
https://github.com/copier-org/copier/security/advisories/GHSA-34mv-rjq9-5mch
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
