Copier is a library and CLI app for rendering project templates. Prior to version 9.11.2, Copier suggests that its safe to generate a project from a safe template, i.e. one that doesnt use unsafe features like custom Jinja extensions which would require passing the --UNSAFE,--trust flag. As it turns out, a safe template can currently include arbitrary files/directories outside the local template clone location by using symlinks along with _preserve_symlinks: false (which is Copiers default setting). Version 9.11.2 patches the issue.
The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Copier | Copier-org | * | 9.11.2 (excluding) |