Junglewise Threat Intelligence

CVE-2025-27145: PYSEC-2026-1278 - copyparty renders unsanitized filenames as HTML when user uploads empty files

CVE-2025-27145 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: copyparty (PyPI). Vendors: PyPI.

Executive brief

copyparty renders unsanitized filenames as HTML when user uploads empty files

Affected products

  • PyPI copyparty

Related threats