๐Ÿ” CVE Alert

CVE-2026-30974

MEDIUM 4.6

Copyparty volflag `nohtml` did not block javascript in svg files

CVSS Score
4.6
EPSS Score
0.0%
EPSS Percentile
0th

Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML files, did not apply to SVG images. A user with write-permission could upload an SVG containing embedded JavaScript, which would execute in the context of whichever user opens it. This has been fixed in v1.20.11.

CWE CWE-79
Vendor 9001
Product copyparty
Published Mar 10, 2026
Last Updated Mar 11, 2026
Stay Ahead of the Next One

Get instant alerts for 9001 copyparty

Be the first to know when new medium vulnerabilities affecting 9001 copyparty are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

9001 / copyparty
< 1.20.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/9001/copyparty/security/advisories/GHSA-m6hv-x64c-27mm github.com: https://github.com/9001/copyparty/commit/1c9f894e149b6be3cc7de81efc93a4ce4766e0e5 github.com: https://github.com/9001/copyparty/releases/tag/v1.20.11