copyparty vulnerabilities
CVEs whose affected-version data names the copyparty package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
10 CVEsRSS
CVE-2026-70657Medium· 4.3Copyparty is a portable file server
Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the conta…
CVE-2026-30974Medium· 4.6copyparty: volflag `nohtml` did not block javascript in svg files
copyparty: volflag `nohtml` did not block javascript in svg files
CVE-2026-27948Medium· 5.4Copyparty vulnerable to reflected XSS via setck parameter
Copyparty vulnerable to reflected XSS via setck parameter
CVE-2025-58753Mediumcopyparty: Sharing a single file does not fully restrict access to other files in source folder
copyparty: Sharing a single file does not fully restrict access to other files in source folder
CVE-2023-41471High· 7.8Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to t…
Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors…
CVE-2025-54796High· 7.5copyparty allows Regex Denial of Service (ReDoS) in the upload listing
copyparty allows Regex Denial of Service (ReDoS) in the upload listing
CVE-2025-54589Medium· 6.3PoCcopyparty Reflected XSS via Filter Parameter
copyparty Reflected XSS via Filter Parameter
CVE-2025-54423Medium· 5.4copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata
copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata
CVE-2025-27145Low· 3.6copyparty renders unsanitized filenames as HTML when user uploads empty files
copyparty renders unsanitized filenames as HTML when user uploads empty files
CVE-2023-37474High· 7.5PoCcopyparty vulnerable to path traversal attack
copyparty vulnerable to path traversal attack