Junglewise Threat Intelligence

CVE-2026-30974: PYSEC-2026-2137 - Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploa

CVE-2026-30974 · Severity: low · CVSS 3.1 · Published 2026-03-10

Technologies: copyparty (PyPI). Vendors: PyPI.

Executive brief

Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML files, did not apply to SVG images. A user with write-permission could upload an SVG containing embedded JavaScript, which would execute in the context of whichever user opens it. This has been fixed in v1.20.11.

Affected products

  • PyPI copyparty

Related threats