copyparty
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting copypartypage 1 of 1
- CVE-2023-37474HIGHCVSS 7.5EG 9.0✓ Fixed in 1.8.22023-07-14
vulnerable: 0.10.0 ... 1.8.1 (226 versions)
Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands …
- CVE-2023-38501MEDIUMCVSS 6.3EG 6.3✓ Fixed in 1.8.72023-07-25
vulnerable: 0.10.0 ... 1.8.6 (230 versions)
copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case outcome of this is being able to move or delete existing fi…
- CVE-2025-27145LOWCVSS 3.6EG 3.6✓ Fixed in 1.16.152025-02-25
vulnerable: 0.10.0 ... 1.9.9 (311 versions)
copyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered low-risk. By handing someone a maliciously-named file, and then tricking them into dragging…
- CVE-2025-54796HIGHCVSS 7.5EG 7.5✓ Fixed in 1.18.92025-08-02
vulnerable: 0.10.0 ... 1.9.9 (330 versions)
Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks t…
Check whether copyparty is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for copyparty CVEs against the assets you own.
Start Free Scan →