← Vulnerability feed

Vulnerability record · CVE-2023-37474 · published 14 July 2023

CVE-2023-37474: Copyparty path traversal in .cpr subfolder exposes files outside web root

99001 · Copyparty

Copyparty versions before 1.8.2 contain a path traversal flaw in the .cpr subfolder, allowing access to files, directories and commands outside the web document root. The issue is fixed in commit 043e3c7d, included in release 1.8.2, and no workarounds exist, so upgrading is the only remedy.

7.5 CVSS 3.1 High EPSS 45% · top 1.3% CWE-22 · Path traversal
7.5CVSS 3.1 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in the `.cpr` subfolder. The Path Traversal attack technique allows an attacker access to files, directories, and commands that reside outside the web document root directory. This issue has been addressed in commit `043e3c7d` which has been included in release 1.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityHigh confidentiality impact, unauthenticated network reachability and a high EPSS percentile with a public exploit-tagged advisory make this a high priority despite no KEV listing.

What it is

Copyparty versions before 1.8.2 contain a path traversal flaw in the .cpr subfolder, allowing access to files, directories and commands outside the web document root. The issue is fixed in commit 043e3c7d, included in release 1.8.2, and no workarounds exist, so upgrading is the only remedy.

Impact

An unauthenticated remote attacker can read files outside the intended document root, potentially exposing configuration, credentials or other sensitive data on the host. The CVSS vector shows high confidentiality impact with no integrity or availability effect.

Attack surface

Reachable over the network via HTTP requests to the .cpr subfolder; the CVSS vector AV:N/AC:L/PR:N/UI:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is 0.4492 (98.7th percentile) and a public advisory is tagged Exploit, indicating meaningful exploitation likelihood.

What to do

  • Upgrade Copyparty to version 1.8.2 or later, which includes the fix commit 043e3c7d.
  • If immediate upgrade is impossible, restrict network access to the Copyparty service to trusted clients only.
  • Block or filter requests targeting the .cpr subfolder at the reverse proxy or WAF.
  • Run Copyparty with least-privilege filesystem permissions so traversal reads cannot reach sensitive files.
  • Monitor vendor advisory GHSA-pxfv-7rr3-2qjg for any updated guidance.

Detection

  • Search HTTP access logs for requests containing .cpr with traversal sequences such as ../ or encoded variants.
  • Alert on requests to .cpr paths returning 200 responses for files outside the expected document root.
  • Review filesystem access logs for reads of sensitive files by the Copyparty process user.
  • Correlate outbound or local file reads by the Copyparty service with unusual client IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-37474 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-414719001 copyparty cross-site scripting vulnerabilityCross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-P…EPSS 0.26%7.5CVE-2025-547969001 copyparty uncontrolled resource consumption vulnerabilityCopyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this f…EPSS 0.42%6.1CVE-2026-279489001 copyparty cross-site scripting vulnerabilityCopyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter `?setck=...`. Ve…EPSS 0.27%6.1CVE-2025-545899001 copyparty cross-site scripting vulnerabilityCopyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, users can filter the results usi…EPSS 2.4%6.1CVE-2025-544239001 copyparty cross-site scripting vulnerabilitycopyparty is a portable file server. In versions up to and including versions 1.18.4, an unauthenticated attacker is able to execute arbitrary JavaSc…EPSS 0.41%6.1CVE-2025-271459001 copyparty cross-site scripting vulnerabilitycopyparty, a portable file server, has a DOM-based cross-site scripting vulnerability in versions prior to 1.16.15. The vulnerability is considered l…EPSS 0.47%6.1CVE-2023-385019001 copyparty cross-site scripting vulnerabilitycopyparty is file server software. Prior to version 1.8.7, the application contains a reflected cross-site scripting via URL-parameter `?k304=...` an…EPSS 9.2%5.4CVE-2026-309749001 copyparty cross-site scripting vulnerabilityCopyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML …EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2023-37474), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.