---
id: CVE-2021-41867
aliases:
  - GHSA-6rvj-pw9w-jcvc
  - PYSEC-2026-696
title: Information disclosure vulnerability in OnionShare
summary: Information disclosure vulnerability in OnionShare
severity: medium
vendor: onionshare-cli
product: onionshare-cli
ecosystem: pip
affected:
  - 'onionshare-cli >= 2.3, < 2.4'
patched:
  - onionshare-cli 2.4
published: '2021-11-19'
updated: '2026-07-06'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-6rvj-pw9w-jcvc'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-41867'
  - url: 'https://github.com/onionshare/onionshare'
  - url: 'https://github.com/onionshare/onionshare/compare/v2.3.3...v2.4'
  - url: 'https://www.ihteam.net/advisory/onionshare'
tags:
  - osv
  - pip
epss: 0.01809
epssPercentile: 0.77648
ingestedAt: '2026-07-08T18:25:46.526Z'
---

## Overview

An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature. 

## Affected packages

- `onionshare-cli >= 2.3, < 2.4`

## Remediation

Upgrade to a patched release:

- `onionshare-cli 2.4`
