MEDIUM 4.3 PyPI

Copyparty vulnerable to file/dirkey confusion

PYSEC-2026-3660 · CVE-2026-70657 · GHSA-x5pq-m9p8-f4vx

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

A valid filekey could potentially be converted into a dirkey, granting read-access to the containing folder.

This issue only affected volumes which simultaneously enable both filekeys and dirkeys, with volflag dk or dks combined with fk or fka.

Both required features are default-disabled, and must be explicitly enabled in the volflags (the "flags" section of a volume).

Ready to move

Start Securing

Free, no credit card | First findings in minutes