top of page
perceptive_background_267k.jpg

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators…

Published:

30 juli 2026 om 22:00:00

Alert date:

31 juli 2026 om 21:02:18

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

A security vulnerability exists in Copier, a library and CLI app for rendering project templates, affecting versions 9.5.0 through 9.16.0. The flaw allows percent-encoded parent-directory segments or encoded path separators in a template URL to match a configured trusted repository prefix before the HTTP server or Git transport decodes the path. This path confusion enables unsafe template features from an untrusted repository outside the configured trusted prefix to execute after user interaction. The vulnerability is classified as a trust bypass via URL encoding/path traversal techniques. No exploitation in the wild has been mentioned, but the risk is significant given the potential for arbitrary code execution through malicious templates. The issue has been patched in version 9.17.0 of Copier. Users are advised to upgrade immediately to the fixed release. The fix is documented in a GitHub security advisory (GHSA-34mv-rjq9-5mch) and a corresponding commit.

Technical details

Mitigation steps:

Affected products:

Copier 9.5.0-9.16.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page