CVE-2026-93353: copyparty SFTP Volume Restriction Bypass via mkdir/rmdir/chattr Handlers

Published Sep 24, 2026
·
Updated

copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside permitted volume boundaries by exploiting three handlers that bypass the xvol volflag enforcement. The mkdir, rmdir, and chattr handlers construct destination paths using vfs.get(), vn.canonical(), and os.path.join() without invoking the chkap access check, enabling attackers to traverse symlinks leaving a volume's top directory and perform unauthorized file creation, deletion, or truncation via SSHFXPSETSTAT operations on paths outside any volume the account is authorized to access.

Affected Software

1 affected component
copyparty copyparty

Event History

Sep 24, 2026
CVE Published
via MITRE·08:29 PM
Data Sourced
via MITRE·08:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:18 PM
DescriptionSeverityWeakness
Dec 20, 58701
Event
via NVD·05:49 AM

Frequently Asked Questions

1

Which deployments are exposed?

Deployments that provide authenticated SFTP access are exposed where a user can traverse a symlink that leads outside the top directory of an authorized volume. The issue affects enforcement of volume boundaries in the SFTP front end.

2

What does an attacker need to exploit this issue?

An attacker needs valid SFTP authentication with low-level privileges and must be able to use the affected mkdir, rmdir, or chattr operations against paths that traverse a symlink outside an allowed volume. No user interaction is required.

3

What actions can exploitation perform outside the authorized volume?

The bypass can allow unauthorized creation, removal, or truncation of arbitrary paths outside volumes the account is authorized to access. The described truncation path uses SSH_FXP_SETSTAT operations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203