CVE-2025-27145: copyparty renders unsanitized filenames as HTML when user uploads empty files
A DOM-Based XSS was discovered in copyparty, a portable fileserver. The vulnerability is considered low-risk.
References
Detect and mitigate CVE-2025-27145 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →