copyparty
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting copypartypage 1 of 1
- CVE-2023-37474HIGHCVSS 7.5EG 9.0✓ Fixed in 1.8.22023-07-14
vulnerable: 0.10.0 ... 1.8.1 (226 versions)
Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands …
- CVE-2023-38501MEDIUMCVSS 6.3EG 6.3✓ Fixed in 1.8.72023-07-25
vulnerable: 0.10.0 ... 1.8.6 (230 versions)
copyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` and `?setck=...`. The worst-case outcome of this is being able to move or delete existing fi…
Check whether copyparty is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for copyparty CVEs against the assets you own.
Start Free Scan →