CVE-2026-54707 | OnionShare up to 2.6.3 Receive mode receive_mode.py ReceiveModeRequest._get_file_stream access control

SecurityVulns

A vulnerability was found in OnionShare up to 2.6.3. It has been declared as problematic. Impacted is the function ReceiveModeRequest._get_file_stream of the file cli/onionshare_cli/web/receive_mode.py of the component Receive mode. The manipulation results in improper access controls.

This vulnerability is cataloged as CVE-2026-54707. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More