{"schema_version":1,"title":"copyparty (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 13 vulnerabilities in copyparty (PyPI): 0 in the last 7 days and 6 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-70657, was published on 18 August 2026.","url":"https://junglewise.ai/threats/technologies/copyparty","json_url":"https://junglewise.ai/threats/technologies/copyparty.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/copyparty","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":13,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":6,"last_365_days":10},"latest":[{"cve":"CVE-2026-70657","cvss":4.3,"epss":0.0033,"slug":"cve-2026-70657-copyparty-file-dirkey-confusion-authorization-bypass","title":"Copyparty file/dirkey confusion authorization bypass","severity":"medium","exploited":false,"published_at":"2026-08-18T15:02:01+00:00","url":"https://junglewise.ai/threats/cve-2026-70657-copyparty-file-dirkey-confusion-authorization-bypass"},{"cve":"CVE-2025-58753","cvss":4,"epss":0.0037,"slug":"cve-2025-58753-copyparty-sharing-a-single-file-does-not-fully-restrict-access-to","title":"PYSEC-2026-1279 - copyparty: Sharing a single file does not fully restrict access to other files in source folder","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:04.197729+00:00","url":"https://junglewise.ai/threats/cve-2025-58753-copyparty-sharing-a-single-file-does-not-fully-restrict-access-to"},{"cve":"CVE-2025-54796","cvss":3.1,"epss":0.0042,"slug":"cve-2025-54796-copyparty-allows-regex-denial-of-service-redos-in-the-upload","title":"PYSEC-2026-1275 - copyparty allows Regex Denial of Service (ReDoS) in the upload listing","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:00.228871+00:00","url":"https://junglewise.ai/threats/cve-2025-54796-copyparty-allows-regex-denial-of-service-redos-in-the-upload"},{"cve":"CVE-2025-54589","cvss":3.1,"epss":0.0242,"slug":"cve-2025-54589-copyparty-reflected-xss-via-filter-parameter","title":"PYSEC-2026-1276 - copyparty Reflected XSS via Filter Parameter","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:59.193561+00:00","url":"https://junglewise.ai/threats/cve-2025-54589-copyparty-reflected-xss-via-filter-parameter"},{"cve":"CVE-2025-54423","cvss":3.1,"epss":0.004,"slug":"cve-2025-54423-copyparty-has-dom-based-xss-vulnerability-when-displaying","title":"PYSEC-2026-1277 - copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:59.039311+00:00","url":"https://junglewise.ai/threats/cve-2025-54423-copyparty-has-dom-based-xss-vulnerability-when-displaying"},{"cve":"CVE-2025-27145","cvss":3.1,"epss":0.0047,"slug":"cve-2025-27145-copyparty-renders-unsanitized-filenames-as-html-when-user-uploads","title":"PYSEC-2026-1278 - copyparty renders unsanitized filenames as HTML when user uploads empty files","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:50.251716+00:00","url":"https://junglewise.ai/threats/cve-2025-27145-copyparty-renders-unsanitized-filenames-as-html-when-user-uploads"},{"cve":"CVE-2026-32109","cvss":3.7,"epss":0.0019,"slug":"cve-2026-32109-copyparty-xss-via-crafted-url-to-folder-with-prologue-html","title":"Copyparty XSS via crafted URL to folder with .prologue.html","severity":"low","exploited":false,"published_at":"2026-03-12T14:22:53+00:00","url":"https://junglewise.ai/threats/cve-2026-32109-copyparty-xss-via-crafted-url-to-folder-with-prologue-html"},{"cve":"CVE-2026-32108","cvss":4,"epss":0.0034,"slug":"cve-2026-32108-9001-copyparty-incorrect-authorization-in-ftp-and-sftp-shares","title":"9001 copyparty incorrect authorization in FTP and SFTP shares","severity":"medium","exploited":false,"published_at":"2026-03-12T14:22:46+00:00","url":"https://junglewise.ai/threats/cve-2026-32108-9001-copyparty-incorrect-authorization-in-ftp-and-sftp-shares"},{"cve":"CVE-2026-30974","cvss":3.1,"epss":0.0034,"slug":"cve-2026-30974-copyparty-volflag-nohtml-did-not-block-javascript-in-svg-files","title":"PYSEC-2026-2137 - Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploa","severity":"low","exploited":false,"published_at":"2026-03-10T18:18:56.22+00:00","url":"https://junglewise.ai/threats/cve-2026-30974-copyparty-volflag-nohtml-did-not-block-javascript-in-svg-files"},{"cve":"CVE-2026-27948","cvss":3.1,"epss":0.0027,"slug":"cve-2026-27948-copyparty-vulnerable-to-reflected-xss-via-setck-parameter","title":"PYSEC-2026-2136 - Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck","severity":"low","exploited":false,"published_at":"2026-02-26T02:16:22.733+00:00","url":"https://junglewise.ai/threats/cve-2026-27948-copyparty-vulnerable-to-reflected-xss-via-setck-parameter"},{"cve":"CVE-2023-41471","cvss":3.1,"epss":0.0026,"slug":"cve-2023-41471-pysec-2025-240-cross-site-scripting-vulnerability-in-copyparty","title":"PYSEC-2025-240 - Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the","severity":"low","exploited":false,"published_at":"2025-08-29T19:15:32.31+00:00","url":"https://junglewise.ai/threats/cve-2023-41471-pysec-2025-240-cross-site-scripting-vulnerability-in-copyparty"},{"cve":"CVE-2023-38501","cvss":3.1,"epss":0.0925,"slug":"cve-2023-38501-copyparty-vulnerable-to-reflected-cross-site-scripting-via-k304","title":"PYSEC-2023-132 - copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k30","severity":"low","exploited":false,"published_at":"2023-07-25T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38501-copyparty-vulnerable-to-reflected-cross-site-scripting-via-k304"},{"cve":"CVE-2023-37474","cvss":3,"epss":0.4492,"slug":"cve-2023-37474-copyparty-vulnerable-to-path-traversal-attack","title":"PYSEC-2023-127 - Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder.","severity":"low","exploited":false,"published_at":"2023-07-14T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-37474-copyparty-vulnerable-to-path-traversal-attack"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"copyparty (PyPI)","slug":"copyparty","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://pypi.org/project/copyparty/","repo_url":"https://github.com/9001/copyparty","description":"A file server and gallery application for sharing files and folders.","url":"https://junglewise.ai/threats/technologies/copyparty"},"most_severe":[{"cve":"CVE-2026-70657","cvss":4.3,"epss":0.0033,"slug":"cve-2026-70657-copyparty-file-dirkey-confusion-authorization-bypass","title":"Copyparty file/dirkey confusion authorization bypass","severity":"medium","exploited":false,"published_at":"2026-08-18T15:02:01+00:00","url":"https://junglewise.ai/threats/cve-2026-70657-copyparty-file-dirkey-confusion-authorization-bypass"},{"cve":"CVE-2025-58753","cvss":4,"epss":0.0037,"slug":"cve-2025-58753-copyparty-sharing-a-single-file-does-not-fully-restrict-access-to","title":"PYSEC-2026-1279 - copyparty: Sharing a single file does not fully restrict access to other files in source folder","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:04.197729+00:00","url":"https://junglewise.ai/threats/cve-2025-58753-copyparty-sharing-a-single-file-does-not-fully-restrict-access-to"},{"cve":"CVE-2026-32108","cvss":4,"epss":0.0034,"slug":"cve-2026-32108-9001-copyparty-incorrect-authorization-in-ftp-and-sftp-shares","title":"9001 copyparty incorrect authorization in FTP and SFTP shares","severity":"medium","exploited":false,"published_at":"2026-03-12T14:22:46+00:00","url":"https://junglewise.ai/threats/cve-2026-32108-9001-copyparty-incorrect-authorization-in-ftp-and-sftp-shares"},{"cve":"CVE-2026-32109","cvss":3.7,"epss":0.0019,"slug":"cve-2026-32109-copyparty-xss-via-crafted-url-to-folder-with-prologue-html","title":"Copyparty XSS via crafted URL to folder with .prologue.html","severity":"low","exploited":false,"published_at":"2026-03-12T14:22:53+00:00","url":"https://junglewise.ai/threats/cve-2026-32109-copyparty-xss-via-crafted-url-to-folder-with-prologue-html"},{"cve":"CVE-2023-38501","cvss":3.1,"epss":0.0925,"slug":"cve-2023-38501-copyparty-vulnerable-to-reflected-cross-site-scripting-via-k304","title":"PYSEC-2023-132 - copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k30","severity":"low","exploited":false,"published_at":"2023-07-25T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38501-copyparty-vulnerable-to-reflected-cross-site-scripting-via-k304"},{"cve":"CVE-2025-54589","cvss":3.1,"epss":0.0242,"slug":"cve-2025-54589-copyparty-reflected-xss-via-filter-parameter","title":"PYSEC-2026-1276 - copyparty Reflected XSS via Filter Parameter","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:59.193561+00:00","url":"https://junglewise.ai/threats/cve-2025-54589-copyparty-reflected-xss-via-filter-parameter"},{"cve":"CVE-2025-27145","cvss":3.1,"epss":0.0047,"slug":"cve-2025-27145-copyparty-renders-unsanitized-filenames-as-html-when-user-uploads","title":"PYSEC-2026-1278 - copyparty renders unsanitized filenames as HTML when user uploads empty files","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:50.251716+00:00","url":"https://junglewise.ai/threats/cve-2025-27145-copyparty-renders-unsanitized-filenames-as-html-when-user-uploads"},{"cve":"CVE-2025-54796","cvss":3.1,"epss":0.0042,"slug":"cve-2025-54796-copyparty-allows-regex-denial-of-service-redos-in-the-upload","title":"PYSEC-2026-1275 - copyparty allows Regex Denial of Service (ReDoS) in the upload listing","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:00.228871+00:00","url":"https://junglewise.ai/threats/cve-2025-54796-copyparty-allows-regex-denial-of-service-redos-in-the-upload"},{"cve":"CVE-2025-54423","cvss":3.1,"epss":0.004,"slug":"cve-2025-54423-copyparty-has-dom-based-xss-vulnerability-when-displaying","title":"PYSEC-2026-1277 - copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:59.039311+00:00","url":"https://junglewise.ai/threats/cve-2025-54423-copyparty-has-dom-based-xss-vulnerability-when-displaying"},{"cve":"CVE-2026-30974","cvss":3.1,"epss":0.0034,"slug":"cve-2026-30974-copyparty-volflag-nohtml-did-not-block-javascript-in-svg-files","title":"PYSEC-2026-2137 - Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploa","severity":"low","exploited":false,"published_at":"2026-03-10T18:18:56.22+00:00","url":"https://junglewise.ai/threats/cve-2026-30974-copyparty-volflag-nohtml-did-not-block-javascript-in-svg-files"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}