VYPR
Medium severity5.4NVD Advisory· Published Jul 31, 2026· Updated Sep 10, 2026

CVE-2026-54707

CVE-2026-54707

Description

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where ReceiveModeRequest._get_file_stream() writes multipart file[] data to disk despite the text-only setting. This issue is fixed in version 2.6.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
onionshare-cliPyPI
< 2.6.42.6.4

Affected products

2

Patches

Vulnerability mechanics

References

4

News mentions

1