File Server Vulnerability in Copyparty Prior to Version 1.20.12
CVE-2026-32109
What is CVE-2026-32109?
Prior to version 1.20.12, Copyparty, a portable file server, was susceptible to a vulnerability that allowed an attacker with read and write permissions to upload a malicious file named .prologue.html. This file could be crafted to execute arbitrary JavaScript in the context of an unsuspecting victim if they clicked a specific link, potentially compromising their session. Notable is the unexpected behavior: while the JavaScript would execute when the target directly accessed the file, it could also be executed via a different crafted URL, which was not intended. Mitigating this risk involves utilizing strict SameSite cookies, although successful exploitation requires the target to click a specially crafted link served from the server itself. This vulnerability has been addressed in version 1.20.12.
Affected Version(s)
copyparty < 1.20.12
