copyparty@1.19.6 vulnerabilities

Portable file server with accelerated resumable uploads, deduplication, WebDAV, FTP, zeroconf, media indexer, video thumbnails, audio transcoding, and write-only folders

Direct Vulnerabilities

Known vulnerabilities in the copyparty package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Missing Authorization

Affected versions of this package are vulnerable to Missing Authorization via the shr global-option. An attacker can access unauthorized sibling files within a shared folder by guessing their filenames.

How to fix Missing Authorization?

Upgrade copyparty to version 1.19.8 or higher.

[,1.19.8)
  • M
Cross-site Scripting (XSS)

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the WEEKEND-PLANS field. An attacker can execute arbitrary code in the context of the affected application by submitting a specially crafted payload.

How to fix Cross-site Scripting (XSS)?

There is no fixed version for copyparty.

[0,)