File Disclosure Vulnerability in OnionShare Tool by OnionShare
CVE-2026-54706

4.8MEDIUM

Key Information:

Vendor

Onionshare

Vendor
CVE Published:
31 July 2026

What is CVE-2026-54706?

OnionShare, an open-source tool designed for secure and anonymous file sharing over the Tor network, has a vulnerability that allows remote users to access local files outside the intended directory. This occurs due to the mishandling of symbolic links in specific functions prior to version 2.6.4. Users are advised to upgrade to this latest version to mitigate the risk of unauthorized file exposure.

Affected Version(s)

onionshare < 2.6.4

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.