File Overwrite Vulnerability in Copier Library and Command-Line Interface
CVE-2025-55214
6.9MEDIUM
What is CVE-2025-55214?
The Copier library and CLI tool for rendering project templates contains a file overwrite vulnerability that affects versions from 7.1.0 up to but not including 9.9.1. This issue arises when a template, deemed as 'safe,' is allowed to generate output outside the designated project directory. Through the use of Copier's built-in Jinja filters, an attacker could craft a malicious template that manipulates paths and overwrites files in locations permissible by the user's permissions. This could lead to unintended file modifications, risking the integrity and security of the system. Users are advised to upgrade to version 9.9.1 or later to mitigate this risk.
Affected Version(s)
copier >= 7.1.0, < 9.9.1