{"id":"CVE-2021-41867","aliases":["GHSA-6rvj-pw9w-jcvc","PYSEC-2026-696"],"title":"Information disclosure vulnerability in OnionShare","summary":"Information disclosure vulnerability in OnionShare","severity":"medium","vendor":"onionshare-cli","product":"onionshare-cli","ecosystem":"pip","affected":["onionshare-cli >= 2.3, < 2.4"],"patched":["onionshare-cli 2.4"],"published":"2021-11-19","updated":"2026-07-06","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-6rvj-pw9w-jcvc","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-41867"},{"url":"https://github.com/onionshare/onionshare"},{"url":"https://github.com/onionshare/onionshare/compare/v2.3.3...v2.4"},{"url":"https://www.ihteam.net/advisory/onionshare"}],"tags":["osv","pip"],"epss":0.01809,"epssPercentile":0.77647,"ingestedAt":"2026-07-08T18:25:46.526Z","slug":"CVE-2021-41867","body":"## Overview\n\nAn information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature. \n\n## Affected packages\n\n- `onionshare-cli >= 2.3, < 2.4`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `onionshare-cli 2.4`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}