๐Ÿ” CVE Alert

CVE-2026-54706

MEDIUM 4.8

OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
0th

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.

CWE CWE-59
Vendor onionshare
Product onionshare
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for onionshare onionshare

Be the first to know when new medium vulnerabilities affecting onionshare onionshare are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

onionshare / onionshare
< 2.6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf github.com: https://github.com/onionshare/onionshare/commit/48f31cfac077fcc9c04c67c2a6dbf87d956f5eec github.com: https://github.com/onionshare/onionshare/releases/tag/v2.6.4