File Disclosure Vulnerability in OnionShare Tool by OnionShare
CVE-2026-54706
4.8MEDIUM
What is CVE-2026-54706?
OnionShare, an open-source tool designed for secure and anonymous file sharing over the Tor network, has a vulnerability that allows remote users to access local files outside the intended directory. This occurs due to the mishandling of symbolic links in specific functions prior to version 2.6.4. Users are advised to upgrade to this latest version to mitigate the risk of unauthorized file exposure.
Affected Version(s)
onionshare < 2.6.4
