PT-2025-31523 · Copyparty · Copyparty

Ju0X

·

Published

2025-07-31

·

Updated

2025-07-31

·

CVE-2025-54589

CVSS v3.1
6.3
VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

Name of the Vulnerable Software and Affected Versions:

Copyparty versions 1.18.6 and below

Description:

Copyparty is a portable file server susceptible to a reflected Cross-Site Scripting (XSS) issue. When accessing the recent uploads page at `/?ru`, the application does not properly escape user-supplied input in the filter parameter, which is directly reflected into a `<script>` block. This allows attackers to inject malicious scripts. The issue affects both authenticated and unauthenticated users.

Recommendations:

Update to version 1.18.7 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-54589
GHSA-8MX2-RJH8-Q3JQ

Affected Products

Copyparty