File Overwrite Vulnerability in Copier Library and Command-Line Interface
CVE-2025-55214

6.9MEDIUM

Key Information:

Vendor

Copier-org

Status
Vendor
CVE Published:
18 August 2025

What is CVE-2025-55214?

The Copier library and CLI tool for rendering project templates contains a file overwrite vulnerability that affects versions from 7.1.0 up to but not including 9.9.1. This issue arises when a template, deemed as 'safe,' is allowed to generate output outside the designated project directory. Through the use of Copier's built-in Jinja filters, an attacker could craft a malicious template that manipulates paths and overwrites files in locations permissible by the user's permissions. This could lead to unintended file modifications, risking the integrity and security of the system. Users are advised to upgrade to version 9.9.1 or later to mitigate this risk.

Affected Version(s)

copier >= 7.1.0, < 9.9.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55214 : File Overwrite Vulnerability in Copier Library and Command-Line Interface