File Server Vulnerability in Copyparty Prior to Version 1.20.12
CVE-2026-32109

3.7LOW

Key Information:

Vendor

9001

Status
Vendor
CVE Published:
11 March 2026

What is CVE-2026-32109?

Prior to version 1.20.12, Copyparty, a portable file server, was susceptible to a vulnerability that allowed an attacker with read and write permissions to upload a malicious file named .prologue.html. This file could be crafted to execute arbitrary JavaScript in the context of an unsuspecting victim if they clicked a specific link, potentially compromising their session. Notable is the unexpected behavior: while the JavaScript would execute when the target directly accessed the file, it could also be executed via a different crafted URL, which was not intended. Mitigating this risk involves utilizing strict SameSite cookies, although successful exploitation requires the target to click a specially crafted link served from the server itself. This vulnerability has been addressed in version 1.20.12.

Affected Version(s)

copyparty < 1.20.12

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.