Vulnerability Description
Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder. This vulnerability was only reachable if both types of keys (filekeys and dirkeys) were manually enabled in the volume flags simultaneously. This issue is fixed in version 1.20.17.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/9001/copyparty/commit/e40755331ba9449993ff482456e6bdd2c6deb95
- https://github.com/9001/copyparty/releases/tag/v1.20.17
- https://github.com/9001/copyparty/security/advisories/GHSA-x5pq-m9p8-f4vx
FAQ
What is CVE-2026-70657?
CVE-2026-70657 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory k...
How severe is CVE-2026-70657?
CVE-2026-70657 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-70657?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.