PT-2025-31523 · Copyparty · Copyparty

Ju0X

·

Published

2025-07-31

·

Updated

2025-08-15

·

CVE-2025-54589

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Copyparty versions 1.18.6 and below
Description Copyparty is a portable file server susceptible to a reflected Cross-Site Scripting (XSS) issue. When accessing the recent uploads page at /?ru, the application does not properly escape user-supplied input in the filter parameter, which is directly reflected into a <script> block. This allows attackers to inject malicious scripts. The issue affects both authenticated and unauthenticated users.
Recommendations Update to version 1.18.7 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-54589
GHSA-8MX2-RJH8-Q3JQ

Affected Products

Copyparty