26 Total advisories
26 Vulnerabilities
0 Malware

Dependency scanning

Check whether copyparty is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.5
PyPI

CVE-2025-54796

copyparty allows Regex Denial of Service (ReDoS) in the upload listing

LOW 3.6
PyPI

CVE-2025-27145

copyparty renders unsanitized filenames as HTML when user uploads empty files

HIGH 7.5
PyPI

CVE-2023-37474

copyparty vulnerable to path traversal attack

MEDIUM 4.3
PyPI

CVE-2026-70657

Copyparty vulnerable to file/dirkey confusion

MEDIUM 4.3
PyPI

CVE-2026-70657

Copyparty vulnerable to file/dirkey confusion

MEDIUM 4.6
PyPI

CVE-2026-30974

copyparty: volflag `nohtml` did not block javascript in svg files

MEDIUM 5.4
PyPI

CVE-2026-27948

Copyparty vulnerable to reflected XSS via setck parameter

MEDIUM 5.4
PyPI

CVE-2026-30974

CVE-2026-30974

MEDIUM 6.1
PyPI

CVE-2026-27948

CVE-2026-27948

HIGH 7.8
PyPI

CVE-2023-41471

CVE-2023-41471

MEDIUM 5.4
PyPI

CVE-2025-54423

copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata

UNKNOWN
PyPI

CVE-2025-58753

copyparty: Sharing a single file does not fully restrict access to other files in source folder

MEDIUM 6.3
PyPI

CVE-2025-54589

copyparty Reflected XSS via Filter Parameter

UNKNOWN
PyPI

CVE-2025-58753

copyparty: Sharing a single file does not fully restrict access to other files in source folder

LOW 3.6
PyPI

CVE-2025-27145

copyparty renders unsanitized filenames as HTML when user uploads empty files

MEDIUM 5.4
PyPI

CVE-2025-54423

copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata

MEDIUM 6.3
PyPI

CVE-2025-54589

copyparty Reflected XSS via Filter Parameter

HIGH 7.5
PyPI

CVE-2025-54796

copyparty allows Regex Denial of Service (ReDoS) in the upload listing

LOW 3.7
PyPI

CVE-2026-32109

Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html`

UNKNOWN
PyPI

CVE-2026-32108

Copyparty ftp/sftp: Sharing a single file did not fully restrict source-folder access

MEDIUM 4.4
PyPI

CVE-2026-32109

CVE-2026-32109

MEDIUM 6.5
PyPI

CVE-2026-32108

CVE-2026-32108

MEDIUM 6.3
PyPI

CVE-2023-38501

copyparty vulnerable to reflected cross-site scripting via k304 parameter

MEDIUM 6.3
PyPI

GHSA-cw7j-v52w-fp5r

copyparty vulnerable to reflected cross-site scripting via hc parameter

MEDIUM 6.1
PyPI

CVE-2023-38501

CVE-2023-38501

UNKNOWN
PyPI

CVE-2023-37474

CVE-2023-37474

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes