Bug 2509828 (CVE-2026-54706) - CVE-2026-54706 onionshare: symlink following in shared directories, allowing unintended disclosure of local files
Summary: CVE-2026-54706 onionshare: symlink following in shared directories, allowing ...
Keywords:
Status: NEW
Alias: CVE-2026-54706
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2509848
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-31 17:01 UTC by OSIDB Bzimport
Modified: 2026-08-24 17:42 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-31 17:01:34 UTC
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.


Note You need to log in before you can comment on or make changes to this bug.