Vulnerability Description
Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| 9001 | Copyparty | < 1.20.9 |
Related Weaknesses (CWE)
References
- https://github.com/9001/copyparty/commit/31b2801fd041f803f4a3d5c12c7d7cb5419048bPatch
- https://github.com/9001/copyparty/security/advisories/GHSA-62cr-6wp5-q43hVendor Advisory
FAQ
What is CVE-2026-27948?
CVE-2026-27948 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Version 1.20.9 fixes the issue.
How severe is CVE-2026-27948?
CVE-2026-27948 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-27948?
Check the references section above for vendor advisories and patch information. Affected products include: 9001 Copyparty.