Launch Week Day 1: Announcing Security Design Review
UNKNOWN PyPI

copyparty: Sharing a single file does not fully restrict access to other files in source folder

GHSA-pxvw-4w88-6x95 · CVE-2025-58753

Published · Modified

Description

There was a missing permission-check in the shares feature (the shr global-option).

When a share is created for just one file inside a folder, it was possible to access the other files inside that folder by guessing the filenames.

It was not possible to descend into subdirectories in this manner; only the sibling files were accessible.

This issue did not affect filekeys or dirkeys.

Ready to move

Start Securing

Free, no credit card | First findings in minutes