Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP server or Git transport decodes the path, allowing unsafe template features from a repository outside the trusted prefix to run after user interaction. This issue is fixed in version 9.17.0. Join the discussion | CVE Database V5 | 07/31/2026, 19:41:55 UTC Added: 07/31/2026, 19:48:39 UTC |
0 Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's prefix match (`copier/_settings.py`) compares the template URL against a trusted prefix with a raw `str.startswith` and no path normalization, while the URL is normalized when the template is actually fetched (`Path.resolve()` for local paths; libcurl dot-segment removal for `https`). A template reference that textually starts with a trusted prefix but contains `..` is therefore granted trust yet resolves to a different, attacker-controlled template, whose `tasks` / `migrations` / `jinja_extensions` then run without the `--trust` prompt — arbitrary command execution. Version 9.15.2 patches the issue. Join the discussion | CVE Database V5 | 07/08/2026, 15:26:08 UTC Added: 07/08/2026, 15:58:56 UTC |
0 Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. Join the discussion | CVE Database V5 | 04/02/2026, 18:09:16 UTC Added: 04/02/2026, 18:40:27 UTC |
0 Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1. Join the discussion | CVE Database V5 | 04/02/2026, 18:07:35 UTC Added: 04/02/2026, 18:40:27 UTC |
CVE-2026-23986 is a medium-severity vulnerability in copier versions prior to 9.11.2 that allows a malicious project template to overwrite arbitrary files outside the intended destination directory by exploiting symbolic link following combined with the _preserve_symlinks: true setting. This occurs without requiring privileges or authentication but does require user interaction to generate a project from a crafted template. The vulnerability enables attackers to cause data corruption or disruption by overwriting files according to the user's write permissions. The issue is patched in version 9.11.2. European organizations using copier for project templating should update promptly to mitigate risk. The vulnerability primarily affects UNIX-like systems where symbolic links are supported and copier is used. Join the discussion | CVE Database V5 | 01/21/2026, 22:20:37 UTC Added: 01/21/2026, 22:35:56 UTC |
CVE-2026-23968 is a medium severity vulnerability in the Copier library and CLI tool used for rendering project templates. Versions prior to 9.11.2 allow safe templates to include arbitrary files or directories outside the intended template location by exploiting symbolic link (symlink) following behavior combined with the default setting `_preserve_symlinks: false`. This can lead to unintended file disclosure or manipulation during template generation. The vulnerability does not require privileges or authentication but does require user interaction to trigger template rendering. The issue is patched in version 9.11.2. European organizations using Copier versions before 9. Join the discussion | CVE Database V5 | 01/21/2026, 22:13:25 UTC Added: 01/21/2026, 22:35:56 UTC |
Showing 1 to 6 of 6 results