Medium severity4.8NVD Advisory· Published Jul 31, 2026· Updated Jul 31, 2026
CVE-2026-54706
CVE-2026-54706
Description
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <2.6.4
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.