THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9gmc-jqmh-3rvm (high) — Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

[GHSA] GHSA-9gmc-jqmh-3rvm (high) — Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

highgithub_advisoriesPublished 2026-08-19

GHSA-9gmc-jqmh-3rvm Severity: high CVE: CVE-2026-53951

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

# Copier: trust-prefix bypass via path traversal runs tasks unprompted

### Summary

In copier `>= 9.5.0, <= 9.15.1`, the `trust` setting's prefix match (`copier/_settings.py`) compares the template URL against a trusted prefix with a raw `str.startswith` and **no

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9gmc-jqmh-3rvm