CVE-2026-30974
EUVD-2026-1071110.03.2026, 18:18
Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML files, did not apply to SVG images. A user with write-permission could upload an SVG containing embedded JavaScript, which would execute in the context of whichever user opens it. This has been fixed in v1.20.11.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| 9001 | copyparty | 𝑥 < 1.20.11 |
𝑥
= Vulnerable software versions