Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
632851
AlmaLinux
4665
Alpaquita
8947
Alpine
4067
Android
3261
Azure Linux
12016
BellSoft Hardened Containers
433
Bitnami
7014
Chainguard
5765
CleanStart
794
CRAN
14
crates.io
2248
Debian
54737
Echo
3198
GHC
3
GIT
81490
GitHub Actions
49
Go
6589
Hackage
30
Hex
58
Julia
618
Linux
15361
Mageia
5877
Maven
6327
MinimOS
28420
npm
217578
NuGet
1663
opam
12
openEuler
6511
openSUSE
12599
OSS-Fuzz
3840
Packagist
6087
Pub
11
PyPI
18738
Red Hat
19496
Rocky Linux
2972
Root
12328
RubyGems
1940
SUSE
20565
SwiftURL
50
Ubuntu
52751
VSCode
18
Wolfi
3711
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-hgjq-p8cr-gg4h
PyPI/copier
Copier
`
_external_data
`
allows path traversal and absolute-path local file read without unsafe mode
01 Apr
Fix available
Severity - 5.5 (Medium)
GHSA-85v3-4m8g-hrh6
PyPI/copier
Copier
`
_subdirectory
`
allows template root escape via parent-directory traversal
01 Apr
Fix available
Severity - 4.4 (Medium)
GHSA-4fqp-r85r-hxqh
PyPI/copier
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
21 Jan
Fix available
Severity - 6.9 (Medium)
GHSA-xjhm-gp88-8pfx
PyPI/copier
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
21 Jan
Fix available
Severity - 6.8 (Medium)
GHSA-p7q8-grrj-3m8w
PyPI/copier
Copier's safe template has filesystem write access outside destination path
18 Aug 2025
Fix available
Severity - 6.9 (Medium)
GHSA-3xw7-v6cj-5q8h
PyPI/copier
Copier's safe template has arbitrary filesystem read/write access
18 Aug 2025
Fix available
Severity - 8.5 (High)
PyPI - OSV