Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:pypi/copier

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP server or Git transport decodes the path, allowing unsafe template features from a repository outside the trusted prefix to run after user interaction. This issue is fixed in version 9.17.0.

Join the discussion

Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's prefix match (`copier/_settings.py`) compares the template URL against a trusted prefix with a raw `str.startswith` and no path normalization, while the URL is normalized when the template is actually fetched (`Path.resolve()` for local paths; libcurl dot-segment removal for `https`). A template reference that textually starts with a trusted prefix but contains `..` is therefore granted trust yet resolves to a different, attacker-controlled template, whose `tasks` / `migrations` / `jinja_extensions` then run without the `--trust` prompt — arbitrary command execution. Version 9.15.2 patches the issue.

Join the discussion

Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1.

Join the discussion

Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _subdirectory setting is documented as the subdirectory to use as the template root. However, the current implementation accepts parent-directory traversal such as .. and uses it directly when selecting the template root. As a result, a template can escape its own directory and make Copier render files from the parent directory without --UNSAFE. This issue has been patched in version 9.14.1.

Join the discussion

CVE-2026-23986 is a medium-severity vulnerability in copier versions prior to 9.11.2 that allows a malicious project template to overwrite arbitrary files outside the intended destination directory by exploiting symbolic link following combined with the _preserve_symlinks: true setting. This occurs without requiring privileges or authentication but does require user interaction to generate a project from a crafted template. The vulnerability enables attackers to cause data corruption or disruption by overwriting files according to the user's write permissions. The issue is patched in version 9.11.2. European organizations using copier for project templating should update promptly to mitigate risk. The vulnerability primarily affects UNIX-like systems where symbolic links are supported and copier is used.

Join the discussion

CVE-2026-23968 is a medium severity vulnerability in the Copier library and CLI tool used for rendering project templates. Versions prior to 9.11.2 allow safe templates to include arbitrary files or directories outside the intended template location by exploiting symbolic link (symlink) following behavior combined with the default setting `_preserve_symlinks: false`. This can lead to unintended file disclosure or manipulation during template generation. The vulnerability does not require privileges or authentication but does require user interaction to trigger template rendering. The issue is patched in version 9.11.2. European organizations using Copier versions before 9.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:pypi/copier
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses