4.3
CVE-2026-70657
- EPSS 0.32%
- Veröffentlicht 18.08.2026 14:59:54
- Zuletzt bearbeitet 19.08.2026 17:20:56
- CVE-Watchlists
- Unerledigt
Copyparty: file/dirkey confusion
Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder. This vulnerability was only reachable if both types of keys (filekeys and dirkeys) were manually enabled in the volume flags simultaneously. This issue is fixed in version 1.20.17.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Hersteller9001
≫
Produkt
copyparty
Version
< 1.20.17
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.246 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/9001/copyparty/security/advisories/GHSA-x5pq-m9p8-f4vx
https://github.com/9001/copyparty/commit/e40755331ba9449993ff482456e6bdd2c6deb950
https://github.com/9001/copyparty/releases/tag/v1.20.17