PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-54706 onionshare CVE debrief

The OnionShare tool, specifically versions prior to 2.6.4, contains a vulnerability that allows remote recipients to read local files outside the selected directory due to the following of symbolic links. This issue arises from the handling of file paths in the cli/onionshare_cli/web/send_base_mode.py file, particularly in the SendBaseModeWeb.set_file_info() and stream_individual_file() functions. The vulnerability has been classified as MEDIUM severity with a CVSS score of 4.8. Users of OnionShare, especially those hosting sensitive information or providing access to sensitive systems, should prioritize updating to version 2.6.4 to address the vulnerability. The CVE record was published on 2026-07-31T17:16:33.723Z and has not been modified since then. Defenders should verify affected systems, review file sharing configurations, and monitor for suspicious activity. This CVE record indicates that OnionShare CLI/Desktop follows symbolic links, allowing remote recipients to read local files outside the selected directory. This issue is fixed in version 2.6.4. Defenders should verify affected systems, review file sharing configurations, and monitor for suspicious activity.

Vendor
onionshare
Product
Unknown
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-31
Original CVE updated
2026-09-10
Advisory published
2026-07-31
Advisory updated
2026-09-10

Who should care

Users of OnionShare, especially those hosting sensitive information or providing access to sensitive systems, should prioritize updating to version 2.6.4 to address the vulnerability. Operators, platform administrators, and security teams should review and restrict file sharing configurations, monitor for suspicious activity, and verify affected systems.

Technical summary

OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4. The vulnerability has a CVSS score of 4.8 and is classified as MEDIUM severity. The affected product context indicates that OnionShare versions prior to 2.6.4 are vulnerable. The defensive impact includes the potential for unauthorized file access. The source-grounded technical framing emphasizes the importance of updating to version 2.6.4 or later and reviewing file sharing configurations.

Defensive priority

Organizations using OnionShare should prioritize updating to version 2.6.4 to address the vulnerability.

Recommended defensive actions

  • Update OnionShare to version 2.6.4 or later
  • Review and restrict file sharing configurations
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The CVE record indicates that OnionShare CLI/Desktop follows symbolic links, allowing remote recipients to read local files outside the selected directory. This issue is fixed in version 2.6.4. Defenders should verify affected systems, review file sharing configurations, and monitor for suspicious activity. The vulnerability has a CVSS score of 4.8 and is classified as MEDIUM severity. Users should prioritize updating to version 2.6.4 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-54706 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-54706

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-54706 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54706

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.