<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 09:20:22 +0000</lastBuildDate>
    <item>
      <title>cnvd-2022-06477</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2022-06477</link>
      <description>cnvd-2022-06477</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2022-06477</guid>
    </item>
    <item>
      <title>EUVD-2026-232841</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232841</link>
      <description>EUVD-2026-232841</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232841</guid>
    </item>
    <item>
      <title>fkie_cve-2022-21690</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21690</link>
      <description>&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not sanitized before being passed to the QT frontend. This path is used in all components for displaying the server access history. This leads to a rendered HTML4 Subset (QT RichText editor) in the Onionshare frontend.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not sanitized before being passed to the QT frontend. This path is used in all components for displaying the server access history. This leads to a rendered HTML4 Subset (QT RichText editor) in the Onionshare frontend.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-21690</guid>
    </item>
    <item>
      <title>GHSA-ch22-x2v3-v6vq — OTF-001: Improper Input Sanitation: The path parameter of the requested URL is not sanitized before being passed to the…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ch22-x2v3-v6vq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onionshare-cli&lt;/p&gt;
&lt;p&gt;Between September 26, 2021 and October 8, 2021, [Radically Open Security](https://www.radicallyopensecurity.com/) conducted a penetration test of OnionShare 2.4, funded by the Open Technology Fund&amp;#39;s [Red Team lab](https://www.opentech.fund/labs/red-team-lab/). This is an issue from that penetration test.&lt;/p&gt;
&lt;p&gt;- Vulnerability ID: OTF-001
- Vulnerability type: Improper Input Sanitization
- Threat level: Elevated&lt;/p&gt;
&lt;p&gt;## Description:&lt;/p&gt;
&lt;p&gt;The `path` parameter of the requested URL is not sanitized before being passed to the QT frontend.&lt;/p&gt;
&lt;p&gt;## Technical description:&lt;/p&gt;
&lt;p&gt;The `path` parameter is not sanitized before being passed to the constructor of the `QLabel`.&lt;/p&gt;
&lt;p&gt;https://github.com/onionshare/onionshare/blob/d08d5f0f32f755f504494d80794886f346fbafdb/desktop/src/onionshare/tab/mode/__init__.py#L499-L509&lt;/p&gt;
&lt;p&gt;https://github.com/onionshare/onionshare/blob/d08d5f0f32f755f504494d80794886f346fbafdb/desktop/src/onionshare/tab/mode/history.py#L456-L483&lt;/p&gt;
&lt;p&gt;https://doc.qt.io/qt-5/qlabel.html#details&lt;/p&gt;
&lt;p&gt;&amp;gt; Warning: When passing a QString to the constructor or calling setText(), make sure to sanitize your input, as QLabel tries to guess whether it displays the text as plain text or as rich text, a subset of HTML 4 markup. You may want to call setTextFormat() explicitly, e.g. in case you expect the text to be in plain format but cannot control the text source (for instance when displaying data loaded from the Web).&lt;/p&gt;
&lt;p&gt;This path is used in all components for displaying the server access history. This leads to a rendered H…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onionshare-cli&lt;/p&gt;
&lt;p&gt;Between September 26, 2021 and October 8, 2021, [Radically Open Security](https://www.radicallyopensecurity.com/) conducted a penetration test of OnionShare 2.4, funded by the Open Technology Fund&amp;#39;s [Red Team lab](https://www.opentech.fund/labs/red-team-lab/). This is an issue from that penetration test.&lt;/p&gt;
&lt;p&gt;- Vulnerability ID: OTF-001
- Vulnerability type: Improper Input Sanitization
- Threat level: Elevated&lt;/p&gt;
&lt;p&gt;## Description:&lt;/p&gt;
&lt;p&gt;The `path` parameter of the requested URL is not sanitized before being passed to the QT frontend.&lt;/p&gt;
&lt;p&gt;## Technical description:&lt;/p&gt;
&lt;p&gt;The `path` parameter is not sanitized before being passed to the constructor of the `QLabel`.&lt;/p&gt;
&lt;p&gt;https://github.com/onionshare/onionshare/blob/d08d5f0f32f755f504494d80794886f346fbafdb/desktop/src/onionshare/tab/mode/__init__.py#L499-L509&lt;/p&gt;
&lt;p&gt;https://github.com/onionshare/onionshare/blob/d08d5f0f32f755f504494d80794886f346fbafdb/desktop/src/onionshare/tab/mode/history.py#L456-L483&lt;/p&gt;
&lt;p&gt;https://doc.qt.io/qt-5/qlabel.html#details&lt;/p&gt;
&lt;p&gt;&amp;gt; Warning: When passing a QString to the constructor or calling setText(), make sure to sanitize your input, as QLabel tries to guess whether it displays the text as plain text or as rich text, a subset of HTML 4 markup. You may want to call setTextFormat() explicitly, e.g. in case you expect the text to be in plain format but cannot control the text source (for instance when displaying data loaded from the Web).&lt;/p&gt;
&lt;p&gt;This path is used in all components for displaying the server access history. This leads to a rendered H…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ch22-x2v3-v6vq</guid>
    </item>
    <item>
      <title>gsd-2022-21690</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-21690</link>
      <description>gsd-2022-21690</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-21690</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11983-1 — python-onionshare-2.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11983-1</link>
      <description>&lt;p&gt;python-onionshare-2.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-onionshare-2.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11983-1</guid>
    </item>
    <item>
      <title>PYSEC-2022-41</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2022-41</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onionshare-cli&lt;/p&gt;
&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not sanitized before being passed to the QT frontend. This path is used in all components for displaying the server access history. This leads to a rendered HTML4 Subset (QT RichText editor) in the Onionshare frontend.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onionshare-cli&lt;/p&gt;
&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not sanitized before being passed to the QT frontend. This path is used in all components for displaying the server access history. This leads to a rendered HTML4 Subset (QT RichText editor) in the Onionshare frontend.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2022-41</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2022-21690</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21690</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: onionshare, Ubuntu:25.04: onionshare&lt;/p&gt;
&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not sanitized before being passed to the QT frontend. This path is used in all components for displaying the server access history. This leads to a rendered HTML4 Subset (QT RichText editor) in the Onionshare frontend.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:24.04:LTS: onionshare, Ubuntu:25.04: onionshare&lt;/p&gt;
&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not sanitized before being passed to the QT frontend. This path is used in all components for displaying the server access history. This leads to a rendered HTML4 Subset (QT RichText editor) in the Onionshare frontend.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21690</guid>
    </item>
  </channel>
</rss>
