CVE-2026-30974: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-30974 is a stored Cross-Site Scripting (XSS) vulnerability in Copyparty, a portable file server, caused by the nohtml volume flag failing to block JavaScript execution in SVG image files. The vulnerability affects all Copyparty versions up to and including 1.20.10 (pip package). It was published by the project maintainer on March 8, 2026, and added to the GitHub Advisory Database on March 10, 2026. The CVSS v3.1 base score is 4.6 (Moderate) per the GitHub Advisory, or 5.4 (Medium) per Feedly's assessment (Github Advisory, Copyparty Security Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The nohtml volflag in Copyparty was designed to prevent JavaScript execution in user-uploaded HTML files by serving them as plaintext, but the implementation did not account for SVG images, which can natively embed and execute JavaScript per the SVG specification. An authenticated user with write permission to a volume could upload a crafted SVG file containing embedded <script> tags or event handler attributes; when any other user opens or views that SVG in their browser, the JavaScript executes in the victim's browser context. The fix (commit 1c9f894) extended the MIME-type safety check to cover SVG and other non-safe MIME types, and introduced a companion noscript volflag that applies a Content-Security-Policy: script-src 'none' header as an additional layer of defense (Copyparty Security Advisory, Fix Commit).

Impact

Successful exploitation allows the attacker's JavaScript payload to execute in the browser context of any user who opens the malicious SVG file. The injected script can perform file operations — moving, deleting, or uploading files — on behalf of the victim using their authenticated session, leading to unauthorized data manipulation and potential data loss. Confidentiality is also partially impacted, as the script could exfiltrate session tokens or file contents accessible to the victim. Availability is not directly impacted (Github Advisory, Copyparty Security Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). Exploitation requires an authenticated account with write permission to at least one volume on a Copyparty instance configured with the nohtml volflag, plus user interaction (a victim must open the malicious SVG). The EPSS score is approximately 0.042% (13th percentile), indicating a low near-term exploitation probability. No threat actor attribution or CISA KEV catalog listing has been identified (Github Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Copyparty instance running version ≤ 1.20.10 with the nohtml volflag enabled on a volume, and obtain or already possess a user account with write permission to that volume.
  2. Craft malicious SVG: Create an SVG file containing embedded JavaScript, for example:
<svg xmlns="http://www.w3.org/2000/svg">
  <script>fetch('/api/upload', {method:'POST', body: new FormData()});</script>
</svg>

The payload can be tailored to move, delete, or exfiltrate files using the Copyparty API on behalf of the victim. 3. Upload the SVG: Use the Copyparty web interface or API to upload the crafted SVG to the target volume. Because nohtml did not filter SVG MIME types in vulnerable versions, the file is stored and served with its original content type. 4. Deliver the link: Share or make visible the URL of the uploaded SVG to a target user (e.g., an administrator) through social engineering, a shared directory listing, or a direct link. 5. Trigger execution: When the victim opens the SVG URL in their browser, the embedded JavaScript executes in their session context, performing unauthorized file operations or exfiltrating data using the victim's credentials (Copyparty Security Advisory, Github Advisory).

Indicators of compromise

  • Network: HTTP GET requests to .svg files on a Copyparty server followed immediately by unexpected API calls (e.g., file upload, move, or delete endpoints) originating from the same client session; outbound requests from the victim's browser to external hosts shortly after opening an SVG.
  • File System: Presence of SVG files in upload directories containing <script> tags, JavaScript event handlers (e.g., onload=, onclick=), or javascript: URIs; unexpected new files, renamed files, or missing files in volumes accessible to users who recently viewed SVG content.
  • Logs: Copyparty access logs showing a user opening an SVG file followed by anomalous API activity (file mutations) within the same session; upload log entries for .svg files from accounts that do not normally upload such content.

Mitigation and workarounds

Upgrade Copyparty to version 1.20.11 or later, which extends the nohtml volflag to treat SVG images as plaintext and introduces the new noscript volflag that applies a Content-Security-Policy: script-src 'none' header for additional protection (Copyparty Release, Fix Commit). As an interim workaround, restrict write permissions on volumes to fully trusted users only, and consider disabling SVG file uploads if they are not required. Administrators can also enable the noscript volflag independently to apply CSP-based script blocking, though nohtml (which forces plaintext serving) is the more robust control (Copyparty Security Advisory).

Community reactions

The vulnerability was reported by researcher VarshankNaik and disclosed responsibly through GitHub's security advisory process. The Copyparty maintainer noted in the v1.20.11 release notes that, per the SVG specification, SVG images executing JavaScript is considered intentional behavior — framing the vulnerability as a gap in the nohtml security control rather than a flaw in SVG handling itself (Copyparty Release). No broader media coverage or significant social media discussion has been identified.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management