PT-2026-24194 · Copyparty · Copyparty
Varshanknaik
·
Published
2026-03-10
·
Updated
2026-03-16
·
CVE-2026-30974
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Copyparty versions prior to 1.20.11
Description
Copyparty’s
nohtml configuration option, designed to block JavaScript execution in uploaded HTML files, did not extend to SVG images. A user with write access could upload an SVG file containing embedded JavaScript. When opened by another user, this JavaScript would execute within their context. This could allow a malicious actor to move, delete, or upload files using the account of the user opening the SVG. The nohtml option correctly prevented JavaScript execution in HTML files but failed to account for SVG images.Recommendations
Update to version 1.20.11 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Copyparty