PatchSiren

onionshare CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM onionshare CVE published 2026-07-31

CVE-2026-54706

The OnionShare tool, specifically versions prior to 2.6.4, contains a vulnerability that allows remote recipients to read local files outside the selected directory due to the following of symbolic links. This issue arises from the handling of file paths in the cli/onionshare_cli/web/send_base_mode.py file, particularly in the SendBaseModeWeb.set_file_info() and stream_individual_file() functions. The vul [truncated]

MEDIUM Onionshare CVE published 2017-01-30

CVE-2016-5026

CVE-2016-5026 is a local privilege and access-control issue in OnionShare before 0.9.1. If a local user pre-created the /tmp/onionshare directory, hs.py could be influenced so the hidden service was modified. The practical impact is integrity loss rather than remote compromise, and it is most relevant on multi-user systems where untrusted local users can write to shared temporary locations.