CVE-2026-70657: Copyparty vulnerable to file/dirkey confusion
A valid filekey could potentially be converted into a dirkey, granting read-access to the containing folder.
This issue only affected volumes which simultaneously enable both filekeys and dirkeys, with volflag dk or dks combined with fk or fka.
Both required features are default-disabled, and must be explicitly enabled in the volflags (the “flags” section of a volume).
References
Code Behaviors & Features
Detect and mitigate CVE-2026-70657 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →