{"id":"CVE-2026-54706","title":"OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network","summary":"OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/sen…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","cwe":["CWE-59"],"vendor":"onionshare-cli","product":"onionshare-cli","affected":["onionshare-cli < 2.6.4"],"patched":["onionshare-cli 2.6.4"],"published":"2026-07-31","updated":"2026-09-10","sourceUpdated":"2026-09-10T20:12:43.783","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54706","references":[{"url":"https://github.com/onionshare/onionshare/commit/48f31cfac077fcc9c04c67c2a6dbf87d956f5eec","label":"security-advisories@github.com"},{"url":"https://github.com/onionshare/onionshare/releases/tag/v2.6.4","label":"security-advisories@github.com"},{"url":"https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf","label":"security-advisories@github.com"},{"url":"https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-22p9-r2f5-22mf"}],"tags":["nvd","ghsa","pip"],"epss":0.003,"epssPercentile":0.22867,"aliases":["GHSA-22p9-r2f5-22mf"],"ecosystem":"pip","ingestedAt":"2026-07-31T17:00:00.047Z","slug":"CVE-2026-54706","body":"## Overview\n\nOnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-54706)\n\nAffected packages:\n\n- `onionshare-cli < 2.6.4`\n\nPatched in:\n\n- `onionshare-cli 2.6.4`\n\nSource: https://github.com/advisories/GHSA-22p9-r2f5-22mf","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":26.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}