Vulnerability record · CVE-2026-30974 · published 10 March 2026
CVE-2026-30974: 9001 copyparty cross-site scripting vulnerability
99001 · Copyparty
Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML files, did not apply to SVG images. A user with write-permission could upload an SVG containing embedded JavaScript, which would execute in the context of whichever user opens it. This has been fixed in v1.20.11.
Description
Copyparty is a portable file server. Prior to v1.20.11., the nohtml config option, intended to prevent execution of JavaScript in user-uploaded HTML files, did not apply to SVG images. A user with write-permission could upload an SVG containing embedded JavaScript, which would execute in the context of whichever user opens it. This has been fixed in v1.20.11.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/9001/copyparty/commit/1c9f894e149b6be3cc7de81efc93a4ce4766e0e5 | Patch |
| https://github.com/9001/copyparty/releases/tag/v1.20.11 | ProductRelease Notes |
| https://github.com/9001/copyparty/security/advisories/GHSA-m6hv-x64c-27mm | Vendor Advisory |
Track CVE-2026-30974 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-30974), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.