Vulnerability Description
copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in a victim's browser due to improper sanitization of multimedia tags in music files, including m3u files. This is fixed in version 1.18.5.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 9001 | Copyparty | < 1.18.5 |
Related Weaknesses (CWE)
References
- https://github.com/9001/copyparty/commit/895880aeb0be0813ddf732487596633f8f9fc3aPatch
- https://github.com/9001/copyparty/releases/tag/v1.18.5Release Notes
- https://github.com/9001/copyparty/security/advisories/GHSA-9q4r-x2hj-jmvrExploitVendor Advisory
FAQ
What is CVE-2025-54423?
CVE-2025-54423 is a vulnerability with a CVSS score of 5.4 (MEDIUM). copyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaScript code in a victim's browser due to improper san...
How severe is CVE-2025-54423?
CVE-2025-54423 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-54423?
Check the references section above for vendor advisories and patch information. Affected products include: 9001 Copyparty.