Product
Copier versions 9.5.0 through 9.15.1 contain an authorization bypass vulnerability in the 'trust' configuration where insufficient path normalization allows attackers to execute arbitrary tasks by traversing out of trusted template prefixes.