CVE-2026-54706

Source
https://cve.org/CVERecord?id=CVE-2026-54706
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54706.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54706
Aliases
Downstream
Related
Published
2026-07-31T16:30:58.062Z
Modified
2026-08-12T03:51:39.177404678Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
Details

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionsharecli/web/sendbasemode.py through SendBaseModeWeb.setfileinfo() and streamindividual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54706.json",
    "cwe_ids": [
        "CWE-59"
    ]
}
References

Affected packages

Git / github.com/onionshare/onionshare

Affected ranges

Type
GIT
Repo
https://github.com/onionshare/onionshare
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.6.4"
        }
    ]
}

Affected versions

0.*
0.2
0.3
0.4
0.5
0.6
0.7
0.7.1
0.8
v0.*
v0.8.1
v0.9
v2.*
v2.6.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54706.json"