THREAT OPS › Threat News › [GHSA] GHSA-22p9-r2f5-22mf (medium) — OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
[GHSA] GHSA-22p9-r2f5-22mf (medium) — OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
GHSA-22p9-r2f5-22mf Severity: medium CVE: CVE-2026-54706
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files
### Summary OnionShare CLI/Desktop 2.6.3 can follow symbolic links inside a selected Share or Website directory and serve the symlink target rather than limiting access to files physically contained in the selected directory. If a user shares a
Indicators of compromise
- 8cc75e1d7e88bd31f7276733449d412bf71c8999sha1
- CVE-2026-54706cve
Original source: https://github.com/advisories/GHSA-22p9-r2f5-22mf