File Handling Issue in OnionShare Tool from OnionShare
CVE-2026-54707
5.4MEDIUM
What is CVE-2026-54707?
OnionShare, an open-source application designed for secure and anonymous file sharing, encountered a file handling vulnerability prior to version 2.6.4. In this version, the application failed to enforce the 'disable_files' setting in its Receive mode, allowing multipart file data to be written to disk even when the mode was intended to be text-only. This flaw could lead to unintended file storage on the system despite the user's intention for text-only interactions. The issue has been rectified in version 2.6.4.
Affected Version(s)
onionshare < 2.6.4
