CVE-2025-58753: copyparty: Sharing a single file does not fully restrict access to other files in source folder
(updated )
There was a missing permission-check in the shares feature (the shr
global-option).
When a share is created for just one file inside a folder, it was possible to access the other files inside that folder by guessing the filenames.
It was not possible to descend into subdirectories in this manner; only the sibling files were accessible.
This issue did not affect filekeys or dirkeys.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-58753 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →