CVE-2026-34730: Copier-Org Copier
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Copier is a library and CLI app for rendering project templates. Prior to version 9.14.1, Copier's _external_data feature allows a template to load YAML files using template-controlled paths. If untrusted templates are in scope, a malicious template can read attacker-chosen YAML-parseable local files that are accessible to the user running Copier and expose their contents in rendered output. This issue has been patched in version 9.14.1.
Affected products
- Copier-Org Copier: before 9.14.1 (fixed in 9.14.1)
Published 2026-04-02. Last modified 2026-07-24.