PT-2026-29668 · Copier · Copier
Evipepota
·
Published
2026-04-01
·
Updated
2026-04-03
·
CVE-2026-34726
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Copier versions prior to 9.14.1
Description
Copier's
subdirectory setting, intended to specify the template root, incorrectly allows parent directory traversal sequences like ... This allows a template to escape its directory and render files from the parent directory without using the --UNSAFE flag. The vulnerability lies in the lack of validation that the resulting path remains within the template directory. The vulnerable code path involves rendering the subdirectory string and using it directly to construct the template root path. This can lead to the rendering of files from unintended locations, potentially including sensitive data or configuration files in the parent directory.Recommendations
Update Copier to version 9.14.1 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Copier