THREAT OPS › Threat News › [GHSA] GHSA-9gmc-jqmh-3rvm (high) — Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
[GHSA] GHSA-9gmc-jqmh-3rvm (high) — Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
GHSA-9gmc-jqmh-3rvm Severity: high CVE: CVE-2026-53951
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
# Copier: trust-prefix bypass via path traversal runs tasks unprompted
### Summary
In copier `>= 9.5.0, <= 9.15.1`, the `trust` setting's prefix match (`copier/_settings.py`) compares the template URL against a trusted prefix with a raw `str.startswith` and **no
Indicators of compromise
- CVE-2026-53951cve
- https://curl.se/libcurl/c/CURLOPT_PATH_AS_IS.htmlurl
Original source: https://github.com/advisories/GHSA-9gmc-jqmh-3rvm