icon

We found results for “

CVE-2025-58753

Good to know:

icon
icon
icon

Date: September 9, 2025

Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the "shr" global-option). When a share was created for just one file inside a folder, it was possible to access the other files inside that folder by guessing the filenames. It was not possible to descend into subdirectories in this manner; only the sibling files were accessible. This issue did not affect filekeys or dirkeys. Version 1.19.8 fixes the issue.

Severity Score

Severity Score

Weakness Type (CWE)

Files or Directories Accessible to External Parties

CWE-552

Missing Authorization

CWE-862

Top Fix

icon

Upgrade Version

Upgrade to version copyparty - 1.19.8;copyparty - 1.19.8;https://github.com/9001/copyparty.git - v1.19.8

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us