GHSA-x5pq-m9p8-f4vxMediumCVSS 4.3

Copyparty vulnerable to file/dirkey confusion

Published
August 18, 2026
Last Modified
August 18, 2026

🔗 CVE IDs covered (1)

📋 Description

A valid filekey could potentially be converted into a dirkey, granting read-access to the containing folder.

This issue only affected volumes which simultaneously enable both filekeys and dirkeys, with volflag dk or dks combined with fk or fka.

Both required features are default-disabled, and must be explicitly enabled in the volflags (the "flags" section of a volume).

🎯 Affected products1

  • pip/copyparty:< 1.20.17

🔗 References (4)