CVE-2026-54706

medium
Published 2026-07-31 · Modified 2026-07-31
CVSS v3
4.8
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS v4 NEW
not yet in upstream
VIR risk
4.8

Description

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.

Predictions

Exploit likelihood
58%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-54706 NameCVE-2026-54706 DescriptionOnionShare follows symlinks in shared directories, allowing unintended disclosure of local files SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Debian Bugs1139717 Vulnerable and fixed packages The table below lists information on source…

CVE-2026-54706

NameCVE-2026-54706
DescriptionOnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1139717

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
onionshare (PTS)bullseye2.2-3+deb11u2vulnerable
bookworm2.6-5~deb12u1vulnerable
trixie2.6.3-1vulnerable
forky, sid2.6.4-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
onionsharesource(unstable)2.6.4-11139717

Notes

[trixie] - onionshare <no-dsa> (Minor issue)
https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - onionshare <no-dsa> (Minor issue)https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf

OS impact

debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected
sid Fixed 2.6.4-1
forky Fixed 2.6.4-1
bullseye Affected
bookworm Affected

Package impact

EcosystemPackageVulnerableFixed
python PyPIonionshare-cli<2.6.42.6.4

References

CWEs

CWE-59

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.