Skip to main content

Files or Directories Accessible to External Parties

CVE-2025-58753

Severity Medium
Score 5.3/10

Summary

Copyparty is a portable file server. In versions through 1.19.7, there was a missing permission-check in the shares feature (the "shr" global-option). When a share was created for just one file inside a folder, it was possible to access the other files inside that folder by guessing the filenames. It was not possible to descend into subdirectories in this manner; only the sibling files were accessible. This issue did not affect filekeys or dirkeys.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-552 - Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Advisory Timeline

  • Published