Technology · PyPI
copyparty (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 13 vulnerabilities in copyparty (PyPI): 0 in the last 7 days and 6 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-70657, was published on 18 August 2026.
- Last 7 days
- 0
- Last 90 days
- 6
- Critical, all time
- 0
- Exploited in the wild
- 0
About copyparty (PyPI)
A file server and gallery application for sharing files and folders.
Latest copyparty (PyPI) vulnerabilities
- CVE-2026-70657: Copyparty file/dirkey confusion authorization bypassmediumCVSS 4.3EPSS 0.3%
- CVE-2025-58753: PYSEC-2026-1279 - copyparty: Sharing a single file does not fully restrict access to other files in source foldermediumCVSS 4EPSS 0.4%
- CVE-2025-54796: PYSEC-2026-1275 - copyparty allows Regex Denial of Service (ReDoS) in the upload listinglowCVSS 3.1EPSS 0.4%
- CVE-2025-54589: PYSEC-2026-1276 - copyparty Reflected XSS via Filter ParameterlowCVSS 3.1EPSS 2.4%
- CVE-2025-54423: PYSEC-2026-1277 - copyparty has DOM-Based XSS vulnerability when displaying multimedia metadatalowCVSS 3.1EPSS 0.4%
- CVE-2025-27145: PYSEC-2026-1278 - copyparty renders unsanitized filenames as HTML when user uploads empty fileslowCVSS 3.1EPSS 0.5%
- CVE-2026-32109: Copyparty XSS via crafted URL to folder with .prologue.htmllowCVSS 3.7EPSS 0.2%
- CVE-2026-32108: 9001 copyparty incorrect authorization in FTP and SFTP sharesmediumCVSS 4EPSS 0.3%
- CVE-2026-30974: PYSEC-2026-2137 - Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent…lowCVSS 3.1EPSS 0.3%
- CVE-2026-27948: PYSEC-2026-2136 - Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site…lowCVSS 3.1EPSS 0.3%
- CVE-2023-41471: PYSEC-2025-240 - Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary…lowCVSS 3.1EPSS 0.3%
- CVE-2023-38501: PYSEC-2023-132 - copyparty is file server software. Prior to version 1.8.7, the application contains a reflected…lowCVSS 3.1EPSS 9.3%
- CVE-2023-37474: PYSEC-2023-127 - Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal…lowCVSS 3EPSS 44.9%
Most severe copyparty (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-70657: Copyparty file/dirkey confusion authorization bypassmediumCVSS 4.3EPSS 0.3%
- CVE-2025-58753: PYSEC-2026-1279 - copyparty: Sharing a single file does not fully restrict access to other files in source foldermediumCVSS 4EPSS 0.4%
- CVE-2026-32108: 9001 copyparty incorrect authorization in FTP and SFTP sharesmediumCVSS 4EPSS 0.3%
- CVE-2026-32109: Copyparty XSS via crafted URL to folder with .prologue.htmllowCVSS 3.7EPSS 0.2%
- CVE-2023-38501: PYSEC-2023-132 - copyparty is file server software. Prior to version 1.8.7, the application contains a reflected…lowCVSS 3.1EPSS 9.3%
- CVE-2025-54589: PYSEC-2026-1276 - copyparty Reflected XSS via Filter ParameterlowCVSS 3.1EPSS 2.4%
- CVE-2025-27145: PYSEC-2026-1278 - copyparty renders unsanitized filenames as HTML when user uploads empty fileslowCVSS 3.1EPSS 0.5%
- CVE-2025-54796: PYSEC-2026-1275 - copyparty allows Regex Denial of Service (ReDoS) in the upload listinglowCVSS 3.1EPSS 0.4%
- CVE-2025-54423: PYSEC-2026-1277 - copyparty has DOM-Based XSS vulnerability when displaying multimedia metadatalowCVSS 3.1EPSS 0.4%
- CVE-2026-30974: PYSEC-2026-2137 - Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent…lowCVSS 3.1EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 5 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/copyparty.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "copyparty (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/copyparty, 26 September 2026.