Reflected Cross-Site Scripting in Copyparty File Server
CVE-2026-27948

5.4MEDIUM

Key Information:

Vendor

9001

Status
Vendor
CVE Published:
26 February 2026

What is CVE-2026-27948?

Copyparty, a versatile portable file server, is susceptible to a reflected cross-site scripting (XSS) vulnerability in versions prior to 1.20.9. This vulnerability can be exploited via manipulated URL parameters, specifically ?setck=.... The exploitation of this XSS flaw can enable attackers to execute arbitrary scripts in the context of a user's browser session, posing significant risks such as data theft or session hijacking. Users are advised to upgrade to version 1.20.9 or later, where this issue has been addressed.

Affected Version(s)

copyparty < 1.20.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.