copyparty: Sharing a single file does not fully restrict access to other files in source folder
Description
Published to the GitHub Advisory Database
Sep 9, 2025
Reviewed
Sep 9, 2025
Published by the National Vulnerability Database
Sep 9, 2025
Last updated
Sep 10, 2025
There was a missing permission-check in the shares feature (the
shr
global-option).When a share is created for just one file inside a folder, it was possible to access the other files inside that folder by guessing the filenames.
It was not possible to descend into subdirectories in this manner; only the sibling files were accessible.
This issue did not affect filekeys or dirkeys.
References