CVE-2025-55201 impacts the Copier library and CLI application prior to version 9.9.1, allowing safe templates to perform arbitrary file read and write operations due to exposed pathlib.Path objects within the Jinja context. This vulnerability is rated as High severity (CVSS 8.5), indicating a significant risk of data compromise and system integrity loss through local access and user interaction. While there is no known active exploitation, publicly available exploit code, or significant community discussion, the potential for a complete compromise of confidentiality, integrity, and availability is high if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Copier-Org | Copier | < 9.9.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.