Copyparty <=1.18.6 - Cross-Site Scripting
Copyparty before 1.18.7 is vulnerable to reflected cross-site scripting (XSS) via the 'filter' parameter in the '/?ru' endpoint. Unsanitized user input is reflected in the HTML response, allowing attackers to execute arbitrary JavaScript in the context of the victim's browser. References: https://github.com/9001/copyparty https://secalerts.co/vulnerability/CVE-2025-54589 https://github.com/9001/copyparty/security/advisories/GHSA-8mx2-rjh8-q3jq https://nvd.nist.gov/vuln/detail/CVE-2025-54589 Remediation: Upgrade Copyparty to version 1.18.7 or later to mitigate this vulnerability.
Used 2.3k times · 1 assets checked · url