Sigurd Spieckermann
7 exploits
Active since Dec 2024
Copier `_subdirectory` allows template root escape via parent-directory traversal
CVSS 4.4
Copier `_external_data` allows path traversal and absolute-path local file read without unsafe mode
CVSS 5.5
Jinja 3.0.0-3.1.4 - Remote Code Execution via Template Filename Control
CVSS 8.8
Copier < 9.9.1 - Path Traversal via Unconstrained Pathlib Path Objects
Copier 7.1.0-9.9.0 - Path Traversal and Arbitrary File Write via Pathjoin Filter
copier < 9.11.2 - Arbitrary File Access via Symlink Following
CVSS 5.5
copier < 9.11.2 - Arbitrary File Write via Symlink Following with _preserve_symlinks
CVSS 7.1