The OnionShare tool, specifically versions prior to 2.6.4, contains a vulnerability that allows remote recipients to read local files outside the selected directory due to the following of symbolic links. This issue arises from the handling of file paths in the cli/onionshare_cli/web/send_base_mode.py file, particularly in the SendBaseModeWeb.set_file_info() and stream_individual_file() functions. The vul [truncated]
CVE-2016-5026 is a local privilege and access-control issue in OnionShare before 0.9.1. If a local user pre-created the /tmp/onionshare directory, hs.py could be influenced so the hidden service was modified. The practical impact is integrity loss rather than remote compromise, and it is most relevant on multi-user systems where untrusted local users can write to shared temporary locations.