Security: copier-org/copier
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Copier safe-template symlink escape during Jinja includeGHSA-rg63-g45r-jc58 published
Aug 19, 2026 by sispModerate -
Copier safe template has arbitrary filesystem read access via .. path traversal in !include tagGHSA-p86q-xwwq-6c64 published
Aug 19, 2026 by sispModerate -
Safe template executes arbitrary code via YAML tagsGHSA-v9wr-3fjh-hg69 published
Aug 4, 2026 by sispHigh -
Safe template executes arbitrary code via Jinja sandbox escape through path and settings objectsGHSA-7537-j7hq-f8p9 published
Aug 4, 2026 by sispHigh -
Percent-encoded path traversal segments in template URLs can allow trusted-prefix escapeGHSA-34mv-rjq9-5mch published
Jul 15, 2026 by sispHigh -
Copier: trust-prefix bypass via path traversal runs tasks unpromptedGHSA-9gmc-jqmh-3rvm published
Jun 13, 2026 by sispHigh -
Copier `_subdirectory` allows template root escape via parent-directory traversalGHSA-85v3-4m8g-hrh6 published
Mar 31, 2026 by sispModerate -
Copier `_external_data` allows path traversal and absolute-path local file read without unsafe modeGHSA-hgjq-p8cr-gg4h published
Mar 31, 2026 by sispModerate -
Safe template has arbitrary filesystem write access via directory symlinks when `_preserve_symlinks: true`GHSA-4fqp-r85r-hxqh published
Jan 21, 2026 by sispModerate -
Safe template has arbitrary filesystem read access via symlinks when `_preserve_symlinks: false`GHSA-xjhm-gp88-8pfx published
Jan 21, 2026 by sispModerate
Learn more about advisories related to copier-org/copier in the GitHub Advisory Database