<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 23:43:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-343448</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343448</link>
      <description>EUVD-2026-343448</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343448</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54706</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54706</link>
      <description>&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54706</guid>
    </item>
    <item>
      <title>GHSA-22p9-r2f5-22mf — OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-22p9-r2f5-22mf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onionshare-cli&lt;/p&gt;
&lt;p&gt;### Summary
OnionShare CLI/Desktop 2.6.3 can follow symbolic links inside a selected Share or Website directory and serve the symlink target rather than limiting access to files physically contained in the selected directory. If a user shares a directory that contains attacker-supplied or otherwise untrusted symlinks, a remote recipient with access to the OnionShare service can read arbitrary local files readable by the OnionShare process that the symlink points to.&lt;/p&gt;
&lt;p&gt;This affects the shipped `onionshare-cli` Python package and the desktop application because both call the same `onionshare_cli.web` file-indexing and streaming code.&lt;/p&gt;
&lt;p&gt;### Details
Tested repository: `https://github.com/onionshare/onionshare` at commit `8cc75e1d7e88bd31f7276733449d412bf71c8999`.&lt;/p&gt;
&lt;p&gt;Affected product evidence:
- `cli/pyproject.toml` declares `onionshare_cli` version `2.6.3`.
- `desktop/pyproject.toml` declares `onionshare` version `2.6.3` and depends on `onionshare_cli` from `../cli`.
- `cli/setup.py` publishes `onionshare-cli` and includes `onionshare_cli.web` plus templates/static resources.
- `desktop/setup.py` publishes `onionshare` and exposes both `onionshare` and `onionshare-cli` console scripts.&lt;/p&gt;
&lt;p&gt;Reachable default/common paths:
- CLI share mode is the default mode when no `--receive`, `--website`, or `--chat` flag is provided (`cli/onionshare_cli/__init__.py:234-241`) and accepts filesystem paths from CLI arguments (`cli/onionshare_cli/__init__.py:184-189`).
- CLI website mode is exposed thro…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onionshare-cli&lt;/p&gt;
&lt;p&gt;### Summary
OnionShare CLI/Desktop 2.6.3 can follow symbolic links inside a selected Share or Website directory and serve the symlink target rather than limiting access to files physically contained in the selected directory. If a user shares a directory that contains attacker-supplied or otherwise untrusted symlinks, a remote recipient with access to the OnionShare service can read arbitrary local files readable by the OnionShare process that the symlink points to.&lt;/p&gt;
&lt;p&gt;This affects the shipped `onionshare-cli` Python package and the desktop application because both call the same `onionshare_cli.web` file-indexing and streaming code.&lt;/p&gt;
&lt;p&gt;### Details
Tested repository: `https://github.com/onionshare/onionshare` at commit `8cc75e1d7e88bd31f7276733449d412bf71c8999`.&lt;/p&gt;
&lt;p&gt;Affected product evidence:
- `cli/pyproject.toml` declares `onionshare_cli` version `2.6.3`.
- `desktop/pyproject.toml` declares `onionshare` version `2.6.3` and depends on `onionshare_cli` from `../cli`.
- `cli/setup.py` publishes `onionshare-cli` and includes `onionshare_cli.web` plus templates/static resources.
- `desktop/setup.py` publishes `onionshare` and exposes both `onionshare` and `onionshare-cli` console scripts.&lt;/p&gt;
&lt;p&gt;Reachable default/common paths:
- CLI share mode is the default mode when no `--receive`, `--website`, or `--chat` flag is provided (`cli/onionshare_cli/__init__.py:234-241`) and accepts filesystem paths from CLI arguments (`cli/onionshare_cli/__init__.py:184-189`).
- CLI website mode is exposed thro…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-22p9-r2f5-22mf</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11169-1 — python3-onionshare-2.6.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11169-1</link>
      <description>&lt;p&gt;python3-onionshare-2.6.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python3-onionshare-2.6.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11169-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3585 — OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3585</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onionshare-cli&lt;/p&gt;
&lt;p&gt;### Summary
OnionShare CLI/Desktop 2.6.3 can follow symbolic links inside a selected Share or Website directory and serve the symlink target rather than limiting access to files physically contained in the selected directory. If a user shares a directory that contains attacker-supplied or otherwise untrusted symlinks, a remote recipient with access to the OnionShare service can read arbitrary local files readable by the OnionShare process that the symlink points to.&lt;/p&gt;
&lt;p&gt;This affects the shipped `onionshare-cli` Python package and the desktop application because both call the same `onionshare_cli.web` file-indexing and streaming code.&lt;/p&gt;
&lt;p&gt;### Details
Tested repository: `https://github.com/onionshare/onionshare` at commit `8cc75e1d7e88bd31f7276733449d412bf71c8999`.&lt;/p&gt;
&lt;p&gt;Affected product evidence:
- `cli/pyproject.toml` declares `onionshare_cli` version `2.6.3`.
- `desktop/pyproject.toml` declares `onionshare` version `2.6.3` and depends on `onionshare_cli` from `../cli`.
- `cli/setup.py` publishes `onionshare-cli` and includes `onionshare_cli.web` plus templates/static resources.
- `desktop/setup.py` publishes `onionshare` and exposes both `onionshare` and `onionshare-cli` console scripts.&lt;/p&gt;
&lt;p&gt;Reachable default/common paths:
- CLI share mode is the default mode when no `--receive`, `--website`, or `--chat` flag is provided (`cli/onionshare_cli/__init__.py:234-241`) and accepts filesystem paths from CLI arguments (`cli/onionshare_cli/__init__.py:184-189`).
- CLI website mode is exposed thro…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: onionshare-cli&lt;/p&gt;
&lt;p&gt;### Summary
OnionShare CLI/Desktop 2.6.3 can follow symbolic links inside a selected Share or Website directory and serve the symlink target rather than limiting access to files physically contained in the selected directory. If a user shares a directory that contains attacker-supplied or otherwise untrusted symlinks, a remote recipient with access to the OnionShare service can read arbitrary local files readable by the OnionShare process that the symlink points to.&lt;/p&gt;
&lt;p&gt;This affects the shipped `onionshare-cli` Python package and the desktop application because both call the same `onionshare_cli.web` file-indexing and streaming code.&lt;/p&gt;
&lt;p&gt;### Details
Tested repository: `https://github.com/onionshare/onionshare` at commit `8cc75e1d7e88bd31f7276733449d412bf71c8999`.&lt;/p&gt;
&lt;p&gt;Affected product evidence:
- `cli/pyproject.toml` declares `onionshare_cli` version `2.6.3`.
- `desktop/pyproject.toml` declares `onionshare` version `2.6.3` and depends on `onionshare_cli` from `../cli`.
- `cli/setup.py` publishes `onionshare-cli` and includes `onionshare_cli.web` plus templates/static resources.
- `desktop/setup.py` publishes `onionshare` and exposes both `onionshare` and `onionshare-cli` console scripts.&lt;/p&gt;
&lt;p&gt;Reachable default/common paths:
- CLI share mode is the default mode when no `--receive`, `--website`, or `--chat` flag is provided (`cli/onionshare_cli/__init__.py:234-241`) and accepts filesystem paths from CLI arguments (`cli/onionshare_cli/__init__.py:184-189`).
- CLI website mode is exposed thro…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3585</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54706</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54706</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: onionshare, Ubuntu:Pro:18.04:LTS: onionshare, Ubuntu:Pro:20.04:LTS: onionshare, Ubuntu:Pro:22.04:LTS: onionshare, Ubuntu:24.04:LTS: onionshare, Ubuntu:26.04:LTS: onionshare&lt;/p&gt;
&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: onionshare, Ubuntu:Pro:18.04:LTS: onionshare, Ubuntu:Pro:20.04:LTS: onionshare, Ubuntu:Pro:22.04:LTS: onionshare, Ubuntu:24.04:LTS: onionshare, Ubuntu:26.04:LTS: onionshare&lt;/p&gt;
&lt;p&gt;OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through SendBaseModeWeb.set_file_info() and stream_individual_file(), allowing remote recipients of Share or Website mode to read local files outside the selected directory. This issue is fixed in version 2.6.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54706</guid>
    </item>
  </channel>
</rss>
