Copyparty Cross-Site Scripting Vulnerability in WEEKEND-PLANS Function

Vulnerability

A cross-site scripting vulnerability has been identified in Copyparty version 1.9.1. This issue allows local attackers to execute arbitrary code by sending a crafted payload to the WEEKEND-PLANS function.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject and execute malicious scripts in the context of the user's browser.

Reproduction

To reproduce this vulnerability, upload a markdown file to the WEEKEND-PLANS function. Include a payload that exploits the cross-site scripting vulnerability, such as a script tag or an event handler. Once the file is uploaded, the injected script will be executed, demonstrating the successful exploitation of the vulnerability.

Added: Aug 29, 2025, 7:25 PM
Updated: Aug 29, 2025, 8:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
10.0
exploitability
6.0
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.