Skip to content

copyparty

v1.20.19 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 15h File Storage & Sync
βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

copyparty file-server file-sharing file-upload-server ftp-server nas-frontend
+2 more
tftp-server webdav-server

Affected surfaces

rce_ssrf

Summary

AI summary

Broad release touches πŸ”§ other changes, 🩹 bugfixes, πŸ§ͺ new features, and recent important news.

Full changelog

there is a discord server with an @everyone in case of future important updates, such as vulnerabilities (most recently 2026-07-27)

⚠️ ATTN: this release fixes a vulnerability in FTP and FTPS (not SFTP)

the FTP-server (default-disabled) would allow uploading to any folder that the copyparty process had permission to write to, but with certain limitations; see GHSA-phv8-wgjp-g4p9

recent important news

πŸ§ͺ new features

  • #1495 wopi integration -- edit office documents in the web-ui (thx @brandon-doornbos!) d57bb0c7 10db4236
    • currently only works with collabora online as wopi client #1574 and there's no docs/examples #1575
  • thumbnails: use embedded cover-image in videos when available 59524018
  • thumbnails: folder-thumbs can be disabled with th-covers: no (volflag or global) 856fada3
  • #1555 macos: add --srch-nfkc to fix searching for filenames / paths in CJK languages a7c99094
    • reduces search performance to around 30% when enabled
  • hooks: xbr / xar did not include old/new abspath as parameters; now they do c122e103

🩹 bugfixes

  • ftp: fix GHSA-phv8-wgjp-g4p9 b331bb1c
  • #1563 moving files between volumes could fail depending on OS and underlying filesystem c70dc7ac
  • fix drag-drop uploading in certain glitchy KDE environments (thx @tilse!) daf144af
  • hooks: xiu crashed if the fork-flag was set (thx @stackxp!) aa862353
  • hooks: xau without json-flag would be given the wark (file hash) instead of the abspath bae77b90
  • shares: fix markdown-viewer (?v) inside shares 6a9437b7
  • ftp: fix logging from xbu hooks 9912a951
  • fix slow boot if a volume had lots of files in its toplevel folder cdb474c8
  • python2.7: fix multithreaded file-hashing 0f2040c3

πŸ”§ other changes

  • #1556 the libvips thumbnailer was demoted to last-fallback due to frequently using excessive amounts of ram ed0be42a
  • if -lo points to an existing file, it will now be appended to instead of overwritten depending on --rlo b6abc33f
  • #1530 nixos: the nix package now uses ffmpeg-headless instead of ffmpeg-full (thx @nyakase!) fface524
  • slightly longer session cookie (was 20, now 24 chars) 537a99df
  • Windows-specific:
    • add a warning regarding the risks of DLL-hijacking when relevant bb40804f
    • fix some trivial PATH-related footguns cea97ac6
    • faster creation of sparse files bc45299b
    • fix detection of filesystem characteristics 6226858b

πŸ’Ύ what to download?

| download link | is it good? | description |
| -- | -- | -- |
| copyparty-sfx.py | βœ… the best πŸ‘ | runs anywhere! only needs python |
| copyparty-en.py | βœ… also good | same but english-only, no i18n |
| a docker image | it's ok | good if you prefer docker πŸ‹ |
| copyparty.exe | ⚠️ acceptable | for win8 or later; built-in thumbnailer |
| u2c.exe | ⚠️ acceptable | CLI uploader as a win7+ exe (video) |
| copyparty.pyz | ⚠️ acceptable | similar to the regular sfx, mostly worse |
| copyparty-en.pyz | ⚠️ acceptable | english-only, no smb-server |
| copyparty32.exe | ⛔️ dangerous | for win7 -- never expose to the internet! |
| cpp-winpe64.exe | ⛔️ dangerous | runs on 64bit WinPE, otherwise useless |
| bootable usb | ┐(οΎŸβˆ€οΎŸ)β”Œ | a surprisingly useful joke (x86_64) |

  • except for u2c.exe, all of the options above are mostly equivalent
  • the zip and tar.gz files below are just source code
  • python packages are available at PyPI

Security Fixes

  • GHSA-phv8-wgjp-g4p9 β€” FTP and FTPS servers allowed uploads to any writable folder, fixed in this release

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track copyparty

Get notified when new releases ship.

Sign up free

About copyparty

Portable file server with accelerated resumable uploads, dedup, WebDAV, SFTP, FTP, TFTP, zeroconf, media indexer, thumbnails++ all in one file

All releases β†’

Related context

Earlier breaking changes

  • v1.20.18 Introduces CSP nonces, possibly breaking some JavaScript‑based plugins.

Beta — feedback welcome: [email protected]