Vulnerabilities in copier-org
8 resultsVexday analysis
A copier-org apresenta um perfil de risco reduzido com apenas 7 CVEs catalogadas e nenhuma sob ataque ativo documentado. A fraqueza dominante é traversal de diretórios (CWE-22), e o risco recente é limitado com apenas 1 vulnerabilidade publicada nos últimos 90 dias, sem vulnerabilidades críticas identificadas.
CVE-2026-34726MEDIUMCopier `_subdirectory` allows template root escape via parent-directory traversalEPSS 0.4%CVE-2026-62999HIGHCopier: Percent-encoded dot segments in template URLs can allow trusted-prefix escape (Incomplete fix for trust-prefix bypass)EPSS 0.4%CVE-2026-34730MEDIUMCopier `_external_data` allows path traversal and absolute-path local file read without unsafe modeEPSS 0.3%CVE-2026-23986MEDIUMCopier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: trueEPSS 0.3%CVE-2025-55214MEDIUMCopier safe template has filesystem write access outside destination pathEPSS 0.3%CVE-2026-53951HIGHCopier: trust-prefix bypass via path traversal runs tasks unpromptedEPSS 0.3%CVE-2025-55201HIGHCopier safe template has arbitrary filesystem read/write accessEPSS 0.3%CVE-2026-23968MEDIUMCopier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: falseEPSS 0.2%