CVE-2026-23968 affects the Copier library and CLI application prior to version 9.11.2. This vulnerability allows a "safe" project template to include arbitrary files or directories outside its local clone location through the use of symlinks, even without the --UNSAFE flag. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to high confidentiality impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or media coverage, though it has garnered significant community discussion on GitHub.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.11.2CPE matchmatch criteria | cpe:2.3:a:copier-org:copier:*:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.