CVE-2026-23986 is a high-severity vulnerability affecting the Copier library and CLI tool prior to version 9.11.2. This flaw allows a malicious template to write to arbitrary directories outside the intended destination path, even when the template is considered "safe," by leveraging directory symlinks and a specific configuration. The vulnerability has a CVSS score of 7.1 (HIGH), indicating that an attacker could achieve high integrity and availability impacts with low attack complexity, though user interaction is required. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or media coverage, but it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.11.2CPE matchmatch criteria | cpe:2.3:a:copier-org:copier:*:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.