mediumCVSS 4.3Vulnerability

CVE-2026-70657

A valid filekey could potentially be converted into a dirkey, granting read-access to the containing folder. This issue only affected volumes which simultaneously enable both filekeys and dirkeys, with volflag `dk` or `dks` combined with `fk` or `fka`. Both required features are default-disabled, and must be explicitly enabled in the volflags (the "flags" section of a volume).

Properties

ghsa_id
GHSA-x5pq-m9p8-f4vx
severity
medium
summary
Copyparty vulnerable to file/dirkey confusion
cvss_score
4.3
cve_id
CVE-2026-70657
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
is_ghsa_only
false
ghsa_published
2026-08-18T15:02:01Z
source_url
https://github.com/advisories/GHSA-x5pq-m9p8-f4vx
ghsa_updated
2026-08-18T15:02:02Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/copyparty

AFFECTS (1)

[Software]pip/copyparty

Explore deeper with Ninja Signal's threat intelligence graph