Copyparty is a portable file server. In versions prior to 1.20.9, an XSS allows for reflected cross-site scripting via URL-parameter ?setck=.... Version 1.20.9 fixes the issue.
?setck=...
"https://github.com/pypa/advisory-database/blob/main/vulns/copyparty/PYSEC-2026-2136.yaml"