CVE-2026-34726: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34726 is a path traversal vulnerability in the Copier project templating tool (Python/pip) that allows a malicious template to escape its designated root directory via the _subdirectory configuration setting. By setting _subdirectory: .. (or an absolute path outside the template root), a template can cause Copier to render files from parent directories without requiring the --UNSAFE flag. All versions of Copier prior to 9.14.1 are affected. The vulnerability was disclosed on March 31, 2026, and carries a CVSS v3.1 base score of 4.4 (Medium) (GitHub Advisory).

Technical details

The root cause is improper path validation (CWE-22: Path Traversal) in the template_copy_root method within copier/_main.py. The vulnerable code constructs the template root path by directly concatenating the user-supplied _subdirectory value to the template's local absolute path (self.template.local_abspath / subdir) without verifying that the resulting path remains within the template directory. The fix (commit cb80a3f) adds a .resolve() call followed by an is_relative_to() check, raising a ForbiddenPathError if the resolved path escapes the template root. Exploitation requires user interaction — a victim must run copier copy or copier update against a malicious template — but no special privileges are needed (GitHub Advisory, Patch Commit).

Impact

A user who runs Copier against an untrusted template can have files from outside the intended template directory read and rendered into the destination project, resulting in low confidentiality and integrity impacts. Practically, this means sensitive files residing in parent directories of the template (e.g., configuration files, credentials, or source code) could be copied into the output directory without the user's knowledge. Availability is not impacted, and the scope is unchanged, limiting the blast radius to the local filesystem accessible to the running user (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of concrete shell commands that reproduce the directory traversal without requiring external systems or elevated privileges (GitHub Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.014% (9th percentile), indicating a low probability of exploitation in the near term (GitHub Advisory).

Exploitation steps

  1. Craft a malicious template: Create a directory structure where the template configuration file (copier.yml) sets _subdirectory: .. (or an absolute path outside the template root), and place sensitive target files in the parent directory.
mkdir -p root/template dst
echo 'loot' > root/loot.txt
printf '%s\n' '_subdirectory: ..' > root/template/copier.yml
  1. Distribute the template: Host the malicious template on a public or private Git repository, or share it directly as a local path, to be used by a victim.
  2. Victim runs Copier: The victim executes copier copy (or copier update) against the malicious template, which does not require --UNSAFE:
copier copy --overwrite root/template dst
  1. Files escape template root: Copier resolves _subdirectory: .. to the parent directory (root/) and walks it as the template root, rendering all files found there — including loot.txt — into the destination directory.
  2. Exfiltrate rendered output: The attacker's template can include Jinja2 expressions to read and embed sensitive file contents into rendered output files, which are then written to the victim's destination directory (GitHub Advisory).

Indicators of compromise

  • File System: Unexpected files appearing in the Copier output/destination directory that originate from parent directories of the template source (e.g., configuration files, .env files, or source code not intended to be part of the template output).
  • File System: Presence of a copier.yml or copier.yaml in a template repository containing _subdirectory: .. or an absolute path value for _subdirectory.
  • Logs: Copier execution logs (if verbose mode is enabled) showing the resolved template_copy_root pointing to a directory above the expected template root.
  • Process: Copier process (versions < 9.14.1) invoked against an external or untrusted template source, particularly with --overwrite flag, resulting in files being written outside the expected scope (GitHub Advisory).

Mitigation and workarounds

Upgrade Copier to version 9.14.1 or later, which introduces a path boundary check that raises a ForbiddenPathError if _subdirectory resolves to a path outside the template root (both relative traversal like .. and absolute paths are blocked) (Copier Release, Patch Commit). As a workaround for users who cannot immediately upgrade, avoid running Copier against templates from untrusted or unreviewed sources, and manually inspect copier.yml/copier.yaml for suspicious _subdirectory values before execution (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management