7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is the default), an attacker can craft a filter which deadlocks the server. This is fixed in version 1.18.9.
Basic Information
ID
CVE-2025-54796
Source
GitHub_M
Published
Aug 1, 2025 at 23:38
Modified
Aug 4, 2025 at 15:19
Affected Product
Vendor
9001
Product
copyparty
Version
< 1.18.9
Affected Versions
9001 copyparty < 1.18.9