DOM-Based Cross-Site Scripting Vulnerability in Copyparty File Server
CVE-2025-27145
3.6LOW
What is CVE-2025-27145?
Copyparty, a portable file server, contains a DOM-based cross-site scripting vulnerability that can be exploited by a malicious user through the drag-and-drop feature of its Web-UI. When an attacker tricks a user into dragging a specially named empty file into the interface, they can execute arbitrary JavaScript code with the same privileges as the targeted user. This behavior can potentially lead to unintended access to sensitive files owned by the user. The vulnerability is present in all versions prior to 1.16.15, which includes the necessary fix.
Affected Version(s)
copyparty < 1.16.15