Dependency scanning
Check whether copyparty is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2025-54796
copyparty allows Regex Denial of Service (ReDoS) in the upload listing
CVE-2025-27145
copyparty renders unsanitized filenames as HTML when user uploads empty files
CVE-2023-37474
copyparty vulnerable to path traversal attack
CVE-2026-70657
Copyparty vulnerable to file/dirkey confusion
CVE-2026-70657
Copyparty vulnerable to file/dirkey confusion
CVE-2026-30974
copyparty: volflag `nohtml` did not block javascript in svg files
CVE-2026-27948
Copyparty vulnerable to reflected XSS via setck parameter
CVE-2026-30974
CVE-2026-30974
CVE-2026-27948
CVE-2026-27948
CVE-2023-41471
CVE-2023-41471
CVE-2025-54423
copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata
CVE-2025-58753
copyparty: Sharing a single file does not fully restrict access to other files in source folder
CVE-2025-54589
copyparty Reflected XSS via Filter Parameter
CVE-2025-58753
copyparty: Sharing a single file does not fully restrict access to other files in source folder
CVE-2025-27145
copyparty renders unsanitized filenames as HTML when user uploads empty files
CVE-2025-54423
copyparty has DOM-Based XSS vulnerability when displaying multimedia metadata
CVE-2025-54589
copyparty Reflected XSS via Filter Parameter
CVE-2025-54796
copyparty allows Regex Denial of Service (ReDoS) in the upload listing
CVE-2026-32109
Copyparty has unexpected JavaScript execution via crafted URL to folder with `.prologue.html`
CVE-2026-32108
Copyparty ftp/sftp: Sharing a single file did not fully restrict source-folder access
CVE-2026-32109
CVE-2026-32109
CVE-2026-32108
CVE-2026-32108
CVE-2023-38501
copyparty vulnerable to reflected cross-site scripting via k304 parameter
GHSA-cw7j-v52w-fp5r
copyparty vulnerable to reflected cross-site scripting via hc parameter
CVE-2023-38501
CVE-2023-38501
CVE-2023-37474
CVE-2023-37474
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes