Medium severity5.3NVD Advisory· Published Oct 4, 2021· Updated Jun 17, 2026
CVE-2021-41867
CVE-2021-41867
Description
An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
onionshare-cliPyPI | >= 2.3, < 2.4 | 2.4 |
Affected products
5cpe:2.3:a:onionshare:onionshare:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:onionshare:onionshare:*:*:*:*:*:*:*:*range: >=2.3,<2.4
- (no CPE)
- ghsa-coords3 versionspkg:pypi/onionshare-clipkg:rpm/opensuse/python-onionshare&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python3-onionshare&distro=openSUSE%20Tumbleweed
>= 2.3, < 2.4+ 2 more
- (no CPE)range: >= 2.3, < 2.4
- (no CPE)range: < 2.4-1.1
- (no CPE)range: < 2.6-4.1
Patches
Vulnerability mechanics
References
5- github.com/onionshare/onionshare/compare/v2.3.3...v2.4nvdPatchThird Party AdvisoryWEB
- www.ihteam.net/advisory/onionshare/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-6rvj-pw9w-jcvcghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-41867ghsaADVISORY
- www.ihteam.net/advisory/onionshareghsaWEB
News mentions
0No linked articles in our index yet.