Intel

AIKIDO-2026-10177

github.com/hashicorp/copywrite is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine

Improper Neutralization of Special Elements Used in a Template Engine Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

71

High Risk

This Affects:

GOgithub.com/hashicorp/copywrite
0.23.0 - 0.24.1
Fixed in 0.24.2

TL;DR

Affected versions of this package improperly parsed .hbs (Handlebars) templates by treating indented lines containing the keyword “copyright” as copyright headers, causing unintended modification of embedded JavaScript code and potential code corruption. An attacker could exploit this behavior by injecting specially crafted template content or configuration data containing the keyword in controlled inputs, triggering logic that alters application code or template behavior, potentially leading to integrity issues, unexpected execution paths, or denial of service during template processing or build pipelines.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/hashicorp/copywrite is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in versions 0.23.0 - 0.24.1.

How to fix this

Upgrade the github.com/hashicorp/copywrite library to the patch version.

Background Info