copier is vulnerable to Path Traversal
60
Medium Risk
Affected versions of this package are vulnerable to path traversal due to improper sanitization of user-controlled paths during Jinja template rendering. The vulnerable code exposed raw string paths in the rendering context, allowing directory escape sequences (e.g., ../../) to be accepted. An attacker could craft malicious input (e.g., setting answers_relpath to ../../../etc/passwd) during template generation. When the application uses this value to resolve file paths, the traversal sequences can redirect operations to unintended file system locations, potentially exposing sensitive data, enabling remote code execution, or compromising the system.
You are affected if you are using a version that falls within the vulnerable range.
copier is vulnerable to Path Traversal in versions 7.1.0 - 9.9.0.
Upgrade the copier library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant