Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Copier-org
Copier-org copier |
|
| Vendors & Products |
Copier-org
Copier-org copier |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1. | |
| Title | Copier `_external_data` allows path traversal and absolute-path local file read without unsafe mode | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-03T13:01:14.081Z
Reserved: 2026-03-30T18:41:20.754Z
Link: CVE-2026-34730
Updated: 2026-04-03T13:01:04.817Z
Status : Awaiting Analysis
Published: 2026-04-02T19:21:32.560
Modified: 2026-04-03T16:10:23.730
Link: CVE-2026-34730
No data.
OpenCVE Enrichment
Updated: 2026-04-03T09:17:01Z