Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x5pq-m9p8-f4vx | Copyparty vulnerable to file/dirkey confusion |
Tue, 18 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder even though both features are disabled by default and must be explicitly enabled in the volume flags. This issue is fixed in version 1.20.17. | |
| Title | Copyparty: file/dirkey confusion | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-18T14:59:54.218Z
Reserved: 2026-08-04T21:48:08.612Z
Link: CVE-2026-70657
No data.
Status : Received
Published: 2026-08-18T15:17:01.077
Modified: 2026-08-18T15:17:01.077
Link: CVE-2026-70657
No data.
OpenCVE Enrichment
No data.
-
CWE-863
Incorrect Authorization
Github GHSA