Home

Description

copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in a victim's browser due to improper sanitization of multimedia tags in music files, including m3u files. This is fixed in version 1.18.5.

PUBLISHED Reserved 2025-07-21 | Published 2025-07-28 | Updated 2025-07-28 | Assigner GitHub_M




MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

< 1.18.5
affected

References

github.com/...yparty/security/advisories/GHSA-9q4r-x2hj-jmvr

github.com/...ommit/895880aeb0be0813ddf732487596633f8f9fc3a6

github.com/9001/copyparty/releases/tag/v1.18.5

cve.org (CVE-2025-54423)

nvd.nist.gov (CVE-2025-54423)

Download JSON