CVE-2025-27145
CVSS 3.1 Score 3.6 of 10 (low)
Details
Summary
CVE-2025-27145 is a low-risk DOM-based cross-site scripting (XSS) vulnerability affecting copyparty, a portable file server, prior to version 1.16.15. An attacker can exploit this flaw by tricking a user into dragging and dropping a maliciously-named empty file into copyparty's Web-UI. This action would execute arbitrary JavaScript with the same privileges as the user, potentially granting unintended read-access to their files. The uploaded file doesn't need to be opened for the script to run; instead, it triggers during the act of uploading. Unlike regular HTML file uploads, this vulnerability executes JavaScript during the upload process, posing a distinct threat. Copyparty version 1.16.15 includes a fix for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.