PT-2025-36951 · Copyparty · Copyparty

9001

·

Published

2025-09-09

·

Updated

2026-03-12

·

CVE-2025-58753

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Copyparty versions prior to 1.19.8
Description: Copyparty is a portable file server. A missing permission-check in the shares feature (shr global-option) allowed access to sibling files within a shared folder by guessing filenames when a share was created for only one file inside that folder. Access was limited to sibling files and did not extend to subdirectories. This issue did not affect filekeys or dirkeys.
Recommendations: Update to version 1.19.8 or later.

Exploit

Fix

Missing Authorization

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2025-58753
GHSA-PXVW-4W88-6X95

Affected Products

Copyparty