File Overwrite Vulnerability in Copier Library and Command-Line Interface
CVE-2025-55214
What is CVE-2025-55214?
The Copier library and CLI tool for rendering project templates contains a file overwrite vulnerability that affects versions from 7.1.0 up to but not including 9.9.1. This issue arises when a template, deemed as 'safe,' is allowed to generate output outside the designated project directory. Through the use of Copier's built-in Jinja filters, an attacker could craft a malicious template that manipulates paths and overwrites files in locations permissible by the user's permissions. This could lead to unintended file modifications, risking the integrity and security of the system. Users are advised to upgrade to version 9.9.1 or later to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
copier >= 7.1.0, < 9.9.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
