CVE-2026-54706

EUVD-2026-51571
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
4.8 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 22.56%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
onionshareonionshare
𝑥
< 2.6.4
CNA
Debian logo
Debian Releases
Debian Product
Codename
onionshare
bookworm
postponed
bullseye
postponed
forky
2.6.4-1
fixed
sid
2.6.4-1
fixed
trixie
2.6.3-1+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
onionshare
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage