
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30974 is a stored Cross-Site Scripting (XSS) vulnerability in Copyparty, a portable file server, caused by the nohtml volume flag failing to block JavaScript execution in SVG image files. The vulnerability affects all Copyparty versions up to and including 1.20.10 (pip package). It was published by the project maintainer on March 8, 2026, and added to the GitHub Advisory Database on March 10, 2026. The CVSS v3.1 base score is 4.6 (Moderate) per the GitHub Advisory, or 5.4 (Medium) per Feedly's assessment (Github Advisory, Copyparty Security Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The nohtml volflag in Copyparty was designed to prevent JavaScript execution in user-uploaded HTML files by serving them as plaintext, but the implementation did not account for SVG images, which can natively embed and execute JavaScript per the SVG specification. An authenticated user with write permission to a volume could upload a crafted SVG file containing embedded <script> tags or event handler attributes; when any other user opens or views that SVG in their browser, the JavaScript executes in the victim's browser context. The fix (commit 1c9f894) extended the MIME-type safety check to cover SVG and other non-safe MIME types, and introduced a companion noscript volflag that applies a Content-Security-Policy: script-src 'none' header as an additional layer of defense (Copyparty Security Advisory, Fix Commit).
Successful exploitation allows the attacker's JavaScript payload to execute in the browser context of any user who opens the malicious SVG file. The injected script can perform file operations — moving, deleting, or uploading files — on behalf of the victim using their authenticated session, leading to unauthorized data manipulation and potential data loss. Confidentiality is also partially impacted, as the script could exfiltrate session tokens or file contents accessible to the victim. Availability is not directly impacted (Github Advisory, Copyparty Security Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). Exploitation requires an authenticated account with write permission to at least one volume on a Copyparty instance configured with the nohtml volflag, plus user interaction (a victim must open the malicious SVG). The EPSS score is approximately 0.042% (13th percentile), indicating a low near-term exploitation probability. No threat actor attribution or CISA KEV catalog listing has been identified (Github Advisory).
nohtml volflag enabled on a volume, and obtain or already possess a user account with write permission to that volume.<svg xmlns="http://www.w3.org/2000/svg">
<script>fetch('/api/upload', {method:'POST', body: new FormData()});</script>
</svg>The payload can be tailored to move, delete, or exfiltrate files using the Copyparty API on behalf of the victim.
3. Upload the SVG: Use the Copyparty web interface or API to upload the crafted SVG to the target volume. Because nohtml did not filter SVG MIME types in vulnerable versions, the file is stored and served with its original content type.
4. Deliver the link: Share or make visible the URL of the uploaded SVG to a target user (e.g., an administrator) through social engineering, a shared directory listing, or a direct link.
5. Trigger execution: When the victim opens the SVG URL in their browser, the embedded JavaScript executes in their session context, performing unauthorized file operations or exfiltrating data using the victim's credentials (Copyparty Security Advisory, Github Advisory).
.svg files on a Copyparty server followed immediately by unexpected API calls (e.g., file upload, move, or delete endpoints) originating from the same client session; outbound requests from the victim's browser to external hosts shortly after opening an SVG.<script> tags, JavaScript event handlers (e.g., onload=, onclick=), or javascript: URIs; unexpected new files, renamed files, or missing files in volumes accessible to users who recently viewed SVG content..svg files from accounts that do not normally upload such content.Upgrade Copyparty to version 1.20.11 or later, which extends the nohtml volflag to treat SVG images as plaintext and introduces the new noscript volflag that applies a Content-Security-Policy: script-src 'none' header for additional protection (Copyparty Release, Fix Commit). As an interim workaround, restrict write permissions on volumes to fully trusted users only, and consider disabling SVG file uploads if they are not required. Administrators can also enable the noscript volflag independently to apply CSP-based script blocking, though nohtml (which forces plaintext serving) is the more robust control (Copyparty Security Advisory).
The vulnerability was reported by researcher VarshankNaik and disclosed responsibly through GitHub's security advisory process. The Copyparty maintainer noted in the v1.20.11 release notes that, per the SVG specification, SVG images executing JavaScript is considered intentional behavior — framing the vulnerability as a gap in the nohtml security control rather than a flaw in SVG handling itself (Copyparty Release). No broader media coverage or significant social media discussion has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."