9.9.1
6 years ago
5 days ago
Known vulnerabilities in the copier package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
copier is an A library for rendering project templates. Affected versions of this package are vulnerable to Arbitrary File Read/Write via the exposure of How to fix Arbitrary File Read/Write? Upgrade | [,9.9.1) |
copier is an A library for rendering project templates. Affected versions of this package are vulnerable to Directory Traversal via the rendering process when generating a directory structure whose rendered path is either a relative parent path or an absolute path. An attacker can overwrite arbitrary files outside the intended destination directory by crafting a malicious template that leverages the How to fix Directory Traversal? Upgrade | [7.1.0,9.9.1) |