Executive brief
Copier is a tool used by developers to create new projects from templates. A security flaw allows malicious templates to access and process files outside of their own folder by using directory traversal shortcuts. If a user processes an untrusted template, it could lead to the unintended exposure or modification of sensitive files on the user's system.
Technical details
A path traversal vulnerability exists in Copier's '_subdirectory' configuration setting. The application fails to validate that the rendered path for the template root remains within the bounds of the template's local directory. By supplying traversal sequences such as '..' in the '_subdirectory' field, an attacker can force Copier to treat the parent directory as the template root. This allows the rendering and potential exposure of files outside the intended template scope without the user explicitly enabling '--UNSAFE' mode. The issue is rooted in the 'template_copy_root' function in '_main.py' which joins the base path with the user-controlled subdirectory string without sanitization. This has been patched in version 9.14.1.
Affected products
- copier-org Copier < 9.14.1
Timeline
- 2026-03-31: patched: Version 9.14.1 released
- 2026-03-31: advisory: GitHub Security Advisory GHSA-85v3-4m8g-hrh6 published
- 2026-04-02: disclosed: CVE-2026-34726 published to NVD