9.11.3
6 years ago
7 days ago
Known vulnerabilities in the copier package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
copier is an A library for rendering project templates. Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following via the symlink resolution process in safe templates when How to fix UNIX Symbolic Link (Symlink) Following? Upgrade | [,9.11.2) |
copier is an A library for rendering project templates. Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following via the symlink resolution process in safe templates when Note: Safe templates are those that don't use unsafe features like custom Jinja extensions, which would require passing the --UNSAFE,--trust flag. How to fix UNIX Symbolic Link (Symlink) Following? Upgrade | [,9.11.2) |