Copyparty Reflected Cross-Site Scripting Vulnerability in Recent Uploads Page

Vulnerability

A reflected cross-site scripting vulnerability has been identified in Copyparty, a portable file server, affecting versions through 1.18.6. The issue arises on the recent uploads page, where users can apply filters using an input field. This field directly reflects its value into a script block without proper escaping, creating an opportunity for cross-site scripting. Both authenticated and unauthenticated users can exploit this vulnerability.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can execute arbitrary JavaScript in the context of the victim's browser.

Reproduction

To reproduce this vulnerability, access the recent uploads page and use the filter input field to submit a script tag, such as one containing JavaScript code like 'alert(1)'.

Remediation

Users can upgrade to Copyparty version 1.18.7 to address this vulnerability.

Added: Jul 31, 2025, 2:21 PM
Updated: Jul 31, 2025, 2:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
1.7
exploitability
7.4
remediation
7.7
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.