Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. copyparty
  4. ›
  5. CVE-2026-70657

CVE-2026-70657: Copyparty vulnerable to file/dirkey confusion

August 18, 2026

A valid filekey could potentially be converted into a dirkey, granting read-access to the containing folder.

This issue only affected volumes which simultaneously enable both filekeys and dirkeys, with volflag dk or dks combined with fk or fka.

Both required features are default-disabled, and must be explicitly enabled in the volflags (the “flags” section of a volume).

References

  • github.com/9001/copyparty/commit/e40755331ba9449993ff482456e6bdd2c6deb950
  • github.com/9001/copyparty/releases/tag/v1.20.17
  • github.com/9001/copyparty/security/advisories/GHSA-x5pq-m9p8-f4vx
  • github.com/advisories/GHSA-x5pq-m9p8-f4vx
  • nvd.nist.gov/vuln/detail/CVE-2026-70657

Code Behaviors & Features

Detect and mitigate CVE-2026-70657 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.20.17

Fixed versions

  • 1.20.17

Solution

Upgrade to version 1.20.17 or above.

Impact 4.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-863: Incorrect Authorization

Source file

pypi/copyparty/CVE-2026-70657.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 22 Sep 2026 12:21:57 +0000.