---
id: CVE-2026-70657
title: Copyparty is a portable file server
summary: >-
  Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with
  the dk or dks directory-key flag combined with the fk or fka file-key flag can
  convert a valid file key into a directory key, granting read access to the
  conta…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-863
vendor: copyparty
product: copyparty
affected:
  - copyparty < 1.20.17
patched:
  - copyparty 1.20.17
published: '2026-08-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T20:09:01.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-70657'
references:
  - url: >-
      https://github.com/9001/copyparty/commit/e40755331ba9449993ff482456e6bdd2c6deb950
    label: security-advisories@github.com
  - url: 'https://github.com/9001/copyparty/releases/tag/v1.20.17'
    label: security-advisories@github.com
  - url: 'https://github.com/9001/copyparty/security/advisories/GHSA-x5pq-m9p8-f4vx'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-x5pq-m9p8-f4vx'
tags:
  - nvd
  - ghsa
  - pip
epss: 0.00331
epssPercentile: 0.23492
aliases:
  - GHSA-x5pq-m9p8-f4vx
ecosystem: pip
ingestedAt: '2026-08-18T15:19:02.394Z'
---

## Overview

Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder. This vulnerability was only reachable if both types of keys (filekeys and dirkeys) were manually enabled in the volume flags simultaneously. This issue is fixed in version 1.20.17.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-70657)

Affected packages:

- `copyparty < 1.20.17`

Patched in:

- `copyparty 1.20.17`

Source: https://github.com/advisories/GHSA-x5pq-m9p8-f4vx
