🛡️ CVE-2026-54706 — onionshare-cli
Description
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
Summary
OnionShare CLI/Desktop 2.6.3 can follow symbolic links inside a selected Share or Website directory and serve the symlink target rather than limiting access to files physically contained in the selected directory. If a user shares a directory that contains attacker-supplied or otherwise untrusted symlinks, a remote recipient with access to the OnionShare service can read arbitrary local files readable by the OnionShare process that the symlink points to.
This affects the shipped onionshare-cli Python package and the desktop application because both call the same onionshare_cli.web file-indexing and streaming code.
Details
Tested repository: https://github.com/onionshare/onionshare at commit 8cc75e1d7e88bd31f7276733449d412bf71c8999.
Affected product evidence:
cli/pyproject.tomldeclaresonionshare_cliversion2.6.3.desktop/pyproject.tomldeclaresonionshareversion2.6.3and depends ononionshare_clifrom../cli.cli/setup.pypublishesonionshare-cliand includesonionshare_cli.webplus templates/static resources.desktop/setup.pypublishesonionshareand exposes bothonionshareandonionshare-cliconsole scripts.
Reachable default/common paths:
- CLI share mode is the default mode when no
--receive,--website, or--chatflag is provided (cli/onionshare_cli/__init__.py:234-241) and accepts filesystem paths from CLI arguments (cli/onionshare_cli/__init__.py:184-189). - CLI website mode is exposed through
--website(cli/onionshare_cli/__init__.py:55-59). - Desktop Website mode calls
self.web.website_mode.set_file_info(self.filenames)before starting (desktop/onionshare/tab/mode/website_mode/__init__.py:281-287). Desktop Share mode callsself.mode.web.share_mode.set_file_info(...)before serving (desktop/onionshare/tab/mode/share_mode/threads.py:42-49). - Documentation describes Website mode as selecting files/folders and serving them over OnionShare (
docs/source/features.rst:109-115).
Root cause:
SendBaseModeWeb.set_file_info()expands a single selected directory into immediate children and recordsos.path.isfile()entries without rejecting symlinks (cli/onionshare_cli/web/send_base_mode.py:73-80,cli/onionshare_cli/web/send_base_mode.py:100-130). On POSIX,os.path.isfile()follows a symlink to a regular file.- Website mode serves any mapped file path through
stream_individual_file()(cli/onionshare_cli/web/website_mode.py:71-97).stream_individual_file()opens the mapped filesystem path directly (cli/onionshare_cli/web/send_base_mode.py:199-313, especiallyopen(file_to_download, "rb")at line 237). - Share mode default
/downloadcan include a symlink target when a single selected folder is expanded into root entries andZipWriter.add_file()callsself.z.write(filename, ...)without rejecting symlinks (cli/onionshare_cli/web/share_mode.py:473-539,cli/onionshare_cli/web/share_mode.py:574-580). - Share mode with
--no-autostop-sharingenables individual file downloads (cli/onionshare_cli/web/share_mode.py:122-125) and reaches the same direct streaming sink (cli/onionshare_cli/web/share_mode.py:430-447). - A partial mitigation exists only for recursive ZIP directory traversal:
ZipWriter.add_dir()skipsos.path.islink(full_filename)(cli/onionshare_cli/web/share_mode.py:582-600). That mitigation does not cover Website mode, Share individual downloads, or Share ZIP generation for root-level symlinks after the single-folder expansion path.
False-positive screening performed:
- URL path traversal without a mapped entry returned 404; the issue is not raw
../traversal but symlink following after a selected directory has been indexed. - Jinja/template escaping and CSP do not mitigate this because the sink is file read/streaming.
- Share mode has a symlink skip in recursive ZIP addition, but local PoC confirmed sibling paths still dereference symlinks.
- The default non-public onion service requires the recipient to know the onion address and private key unless the user opts into public mode; this limits exposure but does not prevent disclosure to an authorized recipient or to anyone with the URL/key.
Affected versions / patched versions:
- Affected versions: unknown; confirmed in version
2.6.3at commit8cc75e1d7e88bd31f7276733449d412bf71c8999. Earlier versions were not tested during this audit. - Patched versions: 2.6.4
Severity:
- Rationale:
AV:Nbecause the file is exposed over the OnionShare HTTP service;AC:Hbecause exploitation requires the victim to share a directory containing an attacker-influenced or untrusted symlink to a sensitive local file;PR:Lbecause the attacker generally needs the OnionShare URL/private key unless the user intentionally runs public mode;UI:Rbecause the OnionShare user must select/start sharing the affected directory;S:Ubecause t
How this vulnerability can be exploited
This issue can be reached over the network, attack complexity is high, an attacker needs low-level privileges on the target. A user must be tricked into taking some action. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity none, availability none.
Weakness class
CVE-2026-54706 is classified as CWE-59: Link Following. The software follows symbolic or hard links without verifying their target, so a planted link can redirect an operation to a sensitive file.
Affected software
CVE-2026-54706 is recorded against 2 packages.
- onionshare-cli (fixed in 2.6.4)
- unknown
Timeline and source
Published on 31 July 2026 and last revised on 4 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.
References
github.com (Web)
github.com (Web)
github.com (Package)
github.com (Web)
Details
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| onionshare-cli | — | 2.6.4 |
| unknown | — | — |
References
Similar Threats
- Medium CVE-2026-54707
- High GHSA-pwjq-6wrh-5w8q
- High CVE-2022-21688
- High CVE-2022-21689
- High CVE-2022-21690
More CVE 2026 advisories
Browse all of CVE 2026 in the advisory index.
Vulnerability Monitoring
Track new vulnerabilities in onionshare-cli
CVE-2026-54706 is rated CVSS 4.8 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.
Set Up Free Alerts →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.