Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/9001/copyparty

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-70657 is an incorrect authorization vulnerability in copyparty, a portable file server. Versions prior to 1.20.17 allow a combination of directory-key and file-key flags to convert a valid file key into a directory key, granting unintended read access to the containing folder. This issue requires manual enabling of both filekeys and dirkeys simultaneously. The vulnerability is fixed in version 1.20.17.

Join the discussion

CVE-2026-32109 is a cross-site scripting (XSS) vulnerability in copyparty versions prior to 1.20.12. It arises when an attacker with both read and write permissions uploads a malicious . prologue.html file and crafts a link that executes arbitrary JavaScript unexpectedly. The vulnerability occurs because the server evaluates the . prologue.html file not only when accessed directly but also when accessed with certain query parameters, leading to unexpected script execution. Exploitation requires the victim to click a crafted link originating from the server itself, which limits the attack scope.

Join the discussion

CVE-2026-32108 is an authorization vulnerability in copyparty versions prior to 1.20.12 affecting the shares feature when used with FTP or SFTP servers made publicly accessible. It allows an authenticated user browsing a shared single file via FTP/SFTP to guess or brute force sibling filenames in the same folder and gain unauthorized read access to those files. This vulnerability does not permit access to subdirectories and only applies under specific configurations involving the shares feature and FTP/SFTP protocols. It is similar to a previously fixed HTTP/HTTPS vulnerability but was not addressed for FTP until this fix. The CVSS score is low (2.3), reflecting limited impact and exploitation complexity. No known exploits are reported in the wild. The issue is fixed in copyparty version 1.

Join the discussion

CVE-2026-30974 is a medium-severity cross-site scripting (XSS) vulnerability in copyparty versions prior to 1.20.11. The issue arises because the 'nohtml' configuration option, designed to block JavaScript execution in user-uploaded HTML files, did not apply to SVG images. This allows a user with write permissions to upload an SVG containing embedded JavaScript, which executes in the context of any user who opens the SVG file. Exploitation requires user interaction and write permissions but does not require elevated privileges beyond that. The vulnerability impacts confidentiality and integrity but not availability. It has been fixed in version 1.20.11.

Join the discussion

Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue.

Join the discussion
CVE-2023-41471: n/aCVE-2023-41471
0

Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors who already have write access to the server, and they can more simply upload HTML files containing JavaScript.

Join the discussion

copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in a victim's browser due to improper sanitization of multimedia tags in music files, including m3u files. This is fixed in version 1.18.5.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Package: pkg:github/9001/copyparty
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses