Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3818
  • PyPI/copier
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted 10 Sep
  • Fix available
  • Severity - 8.8 (High)
GHSA-9gmc-jqmh-3rvm
  • PyPI/copier
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted 19 Aug
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-1272
  • PyPI/copier
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true 07 Jul
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-1274
  • PyPI/copier
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false 07 Jul
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-1273
  • PyPI/copier
Copier's safe template has filesystem write access outside destination path 07 Jul
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-1271
  • PyPI/copier
Copier's safe template has arbitrary filesystem read/write access 07 Jul
  • Fix available
  • Severity - 8.5 (High)
PYSEC-2026-2135
  • PyPI/copier
See record for full details 02 Apr
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-2134
  • PyPI/copier
See record for full details 02 Apr
  • Fix available
  • Severity - 4.4 (Medium)
GHSA-hgjq-p8cr-gg4h
  • PyPI/copier
Copier `_external_data` allows path traversal and absolute-path local file read without unsafe mode 01 Apr
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-85v3-4m8g-hrh6
  • PyPI/copier
Copier `_subdirectory` allows template root escape via parent-directory traversal 01 Apr
  • Fix available
  • Severity - 4.4 (Medium)
GHSA-4fqp-r85r-hxqh
  • PyPI/copier
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true 21 Jan
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-xjhm-gp88-8pfx
  • PyPI/copier
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false 21 Jan
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-p7q8-grrj-3m8w
  • PyPI/copier
Copier's safe template has filesystem write access outside destination path 18 Aug 2025
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-3xw7-v6cj-5q8h
  • PyPI/copier
Copier's safe template has arbitrary filesystem read/write access 18 Aug 2025
  • Fix available
  • Severity - 8.5 (High)