Junglewise Threat Intelligence

CVE-2026-34730: Copier path traversal and local file disclosure in _external_data

CVE-2026-34730 · Severity: medium · CVSS 5.5 · Published 2026-04-02

Technologies: copier (PyPI), Copier-Org Copier. Vendors: PyPI, Copier-Org.

Executive brief

Copier, a tool used for generating project templates, contains a vulnerability that allows malicious templates to read sensitive files on a user's computer. If a user runs Copier using an untrusted template, that template could access and expose local YAML files, such as configuration files or stored secrets, that the user has permission to read. This could lead to the unauthorized disclosure of private data or credentials.

Technical details

A path traversal vulnerability exists in Copier's `_external_data` feature due to a lack of containment checks in the `load_answersfile_data` function. While Copier typically restricts file access to the subproject destination, the `_external_data` implementation fails to validate that rendered paths remain within this boundary. An attacker can craft a malicious template that uses relative (e.g., `../secret.yml`) or absolute paths to read any YAML-parseable file accessible to the user running the CLI. The parsed contents are then exposed in the rendered output. This exploit does not require the `--UNSAFE` flag. The issue is fixed in version 9.14.1 by requiring the `--trust` flag for paths outside the subproject root.

Affected products

  • copier-org Copier < 9.14.1

Timeline

  • 2026-03-31: patched: Fix committed and version 9.14.1 released.
  • 2026-04-02: disclosed: Advisory published.

References

Related threats