id: PYSEC-2025-240 published: "2025-08-29T19:15:32.310Z" modified: "2026-07-13T05:48:21.826020Z" aliases: - CVE-2023-41471 details: "Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors who already have write access to the server, and they can more simply upload HTML files containing JavaScript." affected: - package: name: copyparty ecosystem: PyPI purl: pkg:pypi/copyparty ranges: - type: ECOSYSTEM events: - introduced: "0" - last_affected: 1.9.1 versions: - 0.10.0 - 0.10.1 - 0.10.10 - 0.10.11 - 0.10.12 - 0.10.13 - 0.10.14 - 0.10.15 - 0.10.16 - 0.10.17 - 0.10.18 - 0.10.19 - 0.10.2 - 0.10.20 - 0.10.21 - 0.10.22 - 0.10.3 - 0.10.4 - 0.10.5 - 0.10.6 - 0.10.7 - 0.10.8 - 0.10.9 - 0.11.0 - 0.11.1 - 0.11.10 - 0.11.11 - 0.11.12 - 0.11.13 - 0.11.14 - 0.11.15 - 0.11.16 - 0.11.17 - 0.11.18 - 0.11.19 - 0.11.20 - 0.11.21 - 0.11.22 - 0.11.23 - 0.11.24 - 0.11.26 - 0.11.27 - 0.11.28 - 0.11.29 - 0.11.30 - 0.11.31 - 0.11.32 - 0.11.33 - 0.11.34 - 0.11.35 - 0.11.36 - 0.11.37 - 0.11.38 - 0.11.39 - 0.11.40 - 0.11.41 - 0.11.42 - 0.11.43 - 0.11.44 - 0.11.45 - 0.11.46 - 0.11.47 - 0.11.5 - 0.11.6 - 0.11.7 - 0.11.8 - 0.11.9 - 0.12.1 - 0.12.10 - 0.12.11 - 0.12.12 - 0.12.3 - 0.12.4 - 0.12.5 - 0.12.6 - 0.12.7 - 0.12.8 - 0.12.9 - 0.13.0 - 0.13.1 - 0.13.10 - 0.13.11 - 0.13.12 - 0.13.13 - 0.13.14 - 0.13.2 - 0.13.3 - 0.13.5 - 0.13.6 - 0.13.7 - 0.13.9 - 0.2.3 - 0.3.0 - 0.3.1 - 0.4.0 - 0.4.1 - 0.4.2 - 0.4.3 - 0.5.0 - 0.5.1 - 0.5.2 - 0.5.3 - 0.5.4 - 0.5.5 - 0.5.6 - 0.5.7 - 0.6.0 - 0.6.2 - 0.6.3 - 0.7.0 - 0.7.1 - 0.7.2 - 0.7.3 - 0.7.4 - 0.7.5 - 0.7.6 - 0.7.7 - 0.8.1 - 0.8.3 - 0.9.0 - 0.9.1 - 0.9.10 - 0.9.11 - 0.9.13 - 0.9.3 - 0.9.4 - 0.9.5 - 0.9.6 - 0.9.7 - 0.9.8 - 0.9.9 - 1.0.0 - 1.0.1 - 1.0.10 - 1.0.11 - 1.0.12 - 1.0.13 - 1.0.14 - 1.0.2 - 1.0.3 - 1.0.4 - 1.0.5 - 1.0.7 - 1.0.8 - 1.0.9 - 1.1.0 - 1.1.1 - 1.1.10 - 1.1.11 - 1.1.12 - 1.1.2 - 1.1.3 - 1.1.4 - 1.1.5 - 1.1.6 - 1.1.7 - 1.1.8 - 1.1.9 - 1.2.0 - 1.2.1 - 1.2.10 - 1.2.11 - 1.2.2 - 1.2.3 - 1.2.4 - 1.2.5 - 1.2.6 - 1.2.7 - 1.2.8 - 1.2.9 - 1.3.0 - 1.3.1 - 1.3.10 - 1.3.11 - 1.3.12 - 1.3.13 - 1.3.14 - 1.3.15 - 1.3.16 - 1.3.2 - 1.3.3 - 1.3.4 - 1.3.5 - 1.3.6 - 1.3.7 - 1.3.8 - 1.3.9 - 1.4.0 - 1.4.1 - 1.4.2 - 1.4.3 - 1.4.4 - 1.4.5 - 1.4.6 - 1.5.0 - 1.5.1 - 1.5.2 - 1.5.3 - 1.5.4 - 1.5.5 - 1.5.6 - 1.6.0 - 1.6.1 - 1.6.10 - 1.6.11 - 1.6.12 - 1.6.13 - 1.6.14 - 1.6.15 - 1.6.2 - 1.6.3 - 1.6.4 - 1.6.5 - 1.6.6 - 1.6.7 - 1.6.8 - 1.6.9 - 1.7.0 - 1.7.1 - 1.7.2 - 1.7.3 - 1.7.4 - 1.7.5 - 1.7.6 - 1.8.0 - 1.8.1 - 1.8.2 - 1.8.3 - 1.8.4 - 1.8.6 - 1.8.7 - 1.8.8 - 1.9.0 - 1.9.1 ecosystem_specific: {} references: - type: WEB url: https://github.com/9001/copyparty/releases/tag/v1.9.2 - type: PACKAGE url: https://github.com/9001/copyparty - type: EVIDENCE url: https://github.com/Trinity-SYT-SECURITY/XSS_vuln_issue/blob/main/copyparty.md severity: - type: CVSS_V3 score: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H