CVE-2026-34730
Last modified
CVE-2026-34730 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Copier-Org | Copier | < 9.14.1 |
References
- https://github.com/copier-org/copier/security/advisories/GHSA-hgjq-p8cr-gg4hExploit, Vendor Advisory
- https://github.com/copier-org/copier/security/advisories/GHSA-hgjq-p8cr-gg4hExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-34730?
How severe is CVE-2026-34730?
How do I fix CVE-2026-34730?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34725DbGate is cross-platform database manager. From version 7.0.…8.2
- CVE-2026-34726Copier is a library and CLI app for rendering project templa…4.4
- CVE-2026-34727Vikunja is an open-source self-hosted task management platfo…9.1
- CVE-2026-34728phpMyFAQ is an open source FAQ web application. Prior to ver…8.1
- CVE-2026-34729phpMyFAQ is an open source FAQ web application. Prior to ver…4.8
- CVE-2026-3473Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4…7.1
- CVE-2026-34731WWBN AVideo is an open source video platform. In versions 26…7.5
- CVE-2026-34732WWBN AVideo is an open source video platform. In versions 26…7.5
- CVE-2026-34733WWBN AVideo is an open source video platform. In versions 26…7.3
- CVE-2026-34734HDF5 is software for managing data. In 1.14.1-2 and earlier,…7.8
- CVE-2026-34735The Hytale Modding Wiki is a free service for Hytale mods to…8.7
- CVE-2026-34736Open edX Platform enables the authoring and delivery of onli…5.3
Are you affected by CVE-2026-34730?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
