CVE-2025-58753
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
09/09/2025
Last modified:
18/09/2025
Description
Copyparty is a portable file server. In versions prior to 1.19.8, there was a missing permission-check in the shares feature (the `shr` global-option). When a share was created for just one file inside a folder, it was possible to access the other files inside that folder by guessing the filenames. It was not possible to descend into subdirectories in this manner; only the sibling files were accessible. This issue did not affect filekeys or dirkeys. Version 1.19.8 fixes the issue.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:9001:copyparty:*:*:*:*:*:*:*:* | 1.19.8 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



