MEDIUM 4.3 PyPI
Copyparty vulnerable to file/dirkey confusion
PYSEC-2026-3660 · CVE-2026-70657 · GHSA-x5pq-m9p8-f4vx
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A valid filekey could potentially be converted into a dirkey, granting read-access to the containing folder.
This issue only affected volumes which simultaneously enable both filekeys and dirkeys, with volflag dk or dks combined with fk or fka.
Both required features are default-disabled, and must be explicitly enabled in the volflags (the "flags" section of a volume).
References
- WEB https://github.com/9001/copyparty/security/advisories/GHSA-x5pq-m9p8-f4vx
- WEB https://github.com/9001/copyparty/commit/e40755331ba9449993ff482456e6bdd2c6deb950
- PACKAGE https://github.com/9001/copyparty
- WEB https://github.com/9001/copyparty/releases/tag/v1.20.17
- PACKAGE https://pypi.org/project/copyparty
- ADVISORY https://github.com/advisories/GHSA-x5pq-m9p8-f4vx
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-70657
Ready to move
Start Securing
Free, no credit card | First findings in minutes