© 2025-2026 PySpect
First version without a known vulnerability: 9.15.2
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
Fixed in: 9.15.2
Copier `_external_data` allows path traversal and absolute-path local file read without unsafe mode
Fixed in: 9.14.1
Copier `_subdirectory` allows template root escape via parent-directory traversal
Fixed in: 9.14.1
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Fixed in: 9.11.2
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
Fixed in: 9.11.2
Copier's safe template has filesystem write access outside destination path
Fixed in: 9.9.1
Copier's safe template has arbitrary filesystem read/write access
Fixed in: 9.9.1