This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+2 more
Affected surfaces
ReleasePort's take
Moderate signalThe release patches CVE-2026-27948, an XSS vulnerability.
Why it matters: CVE severity is high (scoreβ―90); patch immediately to prevent web UI exploitation.
Summary
AI summaryBroad release touches π§ other changes, π§ͺ new features, π©Ή bugfixes, and π fun facts.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Fixes CVE-2026-27948 XSS vulnerability. Fixes CVE-2026-27948 XSS vulnerability. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Feature | Medium |
Adds option to generate music spectrograms with logarithmic frequency scale. Adds option to generate music spectrograms with logarithmic frequency scale. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Feature | Medium |
Allows users with read-access to create get-only shares. Allows users with read-access to create get-only shares. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Feature | Medium |
Adds support for the s6 service notification protocol. Adds support for the s6 service notification protocol. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Feature | Medium |
Enables renaming or removal of the toplevel folder in download-as-zip/tar via `&name=` URL parameter. Enables renaming or removal of the toplevel folder in download-as-zip/tar via `&name=` URL parameter. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Feature | Medium |
Adds option to set custom name/path for ffmpeg/ffprobe binaries. Adds option to set custom name/path for ffmpeg/ffprobe binaries. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Feature | Medium |
Adds audio playback support for MKA files. Adds audio playback support for MKA files. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Bugfix | Medium |
Fixes get-only shares not expiring when the creator is removed. Fixes get-only shares not expiring when the creator is removed. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Bugfix | Medium |
Fixes toggling between cropped/fullβsize cover art for music. Fixes toggling between cropped/fullβsize cover art for music. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Bugfix | Medium |
Fixes file listing breakage caused by files from the year 30828. Fixes file listing breakage caused by files from the year 30828. Source: llm_adapter@2026-05-26 Confidence: high |
β |
| Bugfix | Low |
Fixes JavaScript crash when dragging a picture out of the browser. Fixes JavaScript crash when dragging a picture out of the browser. Source: granite4.1:30b@2026-05-26-audit Confidence: low |
β |
| Bugfix | Low |
Resolves issue with "fancy markdown editor" not working on phones. Resolves issue with "fancy markdown editor" not working on phones. Source: granite4.1:30b@2026-05-26-audit Confidence: low |
β |
Full changelog
- read-only demo server at https://a.ocv.me/pub/demo/
- docker image β± similar software β± client testbed
there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2026-03-08)
recent important news
- v1.20.9 (2026-02-25) fixed CVE-2026-27948 (XSS)
π§ͺ new features
- #1463 opds: improved compatibility with various clients (thx @kamaeff!) 9068ec6a
- #1485 users with read-access can now create get-only shares (thx @Scotsguy!) 0bb80e92
- #1466 support the s6 service notification protocol (thx @mobin-2008!) 8c201b84 ca406472
- download-as-zip/tar: the toplevel folder can be renamed with url-param
&name=fooor entirely removed with&namecc5420a3 - #1487 option to generate music spectrograms with logarithmic frequency scale (thx @9hax!) 83dc20f3
- option to set custom name/path for ffmpeg/ffprobe binaries 5e806ec1
- #1489 audio playback of mka files
π©Ή bugfixes
- #1480 #1482 fix get-only shares not expiring if the creator is removed (thx @celinke97 and @Scotsguy!) 3b53a228
- #1474 toggling between cropped/fullsize coverart for music didn't work 926c6e81
- #1470 files from the year 30828 would break file listing 27031f73
- #1494 fix js-crash when dragging a pic from the gallery out of the browser (thx @icxes!) 7d81b9e8
- "fancy markdown editor" didn't work on phones 6183540c
- improve signal handling f4f97b6c
- if I messed something up then
--sig-thror send 7x sigterm
- if I messed something up then
π§ other changes
- docker: the arm32 build of the iv image has graduated 6e75faa6
copyparty/ivis now only available fori386/x86_64/aarch64
- docker: rawpy is no longer bundled; now using libraw directly 348b4bb5
- creating thumbnails of .raw photos is now MUCH slower but quality is also much better
- partyfuse: switch to mfusepy; adds fuse3 support and improves performance b2401ff1
- additional advisory tiers for use with the vulnerability-checker 4e9ad781
- clarify behavior of
xvolregarding permissions e3271830 - packaging/docs:
- #1479 freebsd: fix deps in rc.d (thx @Kansattica!) f432ef6d
- #1458 macos docs (thx @ilotoki0804!) d7eb556c
π fun facts
- there will be a tiny handful of copyparty stickers at dokomi this weekend
πΎ what to download?
| download link | is it good? | description |
| -- | -- | -- |
| copyparty-sfx.py | β
the best π | runs anywhere! only needs python |
| copyparty-en.py | β
also good | same but english-only, no i18n |
| a docker image | it's ok | good if you prefer docker π |
| copyparty.exe | β οΈ acceptable | for win8 or later; built-in thumbnailer |
| u2c.exe | β οΈ acceptable | CLI uploader as a win7+ exe (video) |
| copyparty.pyz | β οΈ acceptable | similar to the regular sfx, mostly worse |
| copyparty-en.pyz | β οΈ acceptable | english-only, no smb-server |
| copyparty32.exe | βοΈ dangerous | for win7 -- never expose to the internet! |
| cpp-winpe64.exe | βοΈ dangerous | runs on 64bit WinPE, otherwise useless |
| bootable usb | β(οΎβοΎ)β | a surprisingly useful joke (x86_64) |
Breaking Changes
- Docker iv image arm32 build removed; now only i386, x86_64, and aarch64 are supported
Security Fixes
- CVE-2026-27948
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About copyparty
Portable file server with accelerated resumable uploads, dedup, WebDAV, SFTP, FTP, TFTP, zeroconf, media indexer, thumbnails++ all in one file
Beta — feedback welcome: [email protected]