Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-54707

7 дней назад

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where ReceiveModeRequest._get_file_stream() writes multipart file[] data to disk despite the text-only setting. This issue is fixed in version 2.6.4.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-54707

7 дней назад

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where ReceiveModeRequest._get_file_stream() writes multipart file[] data to disk despite the text-only setting. This issue is fixed in version 2.6.4.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2026-54707

7 дней назад

OnionShare is an open source tool that lets you securely and anonymous ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-v833-3823-cmhp

8 дней назад

OnionShare Receive mode writes uploaded files even when file uploads are disabled

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-54707

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where ReceiveModeRequest._get_file_stream() writes multipart file[] data to disk despite the text-only setting. This issue is fixed in version 2.6.4.

CVSS3: 5.4
0%
Низкий
7 дней назад
nvd логотип
CVE-2026-54707

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in cli/onionshare_cli/web/receive_mode.py, where ReceiveModeRequest._get_file_stream() writes multipart file[] data to disk despite the text-only setting. This issue is fixed in version 2.6.4.

CVSS3: 5.4
0%
Низкий
7 дней назад
debian логотип
CVE-2026-54707

OnionShare is an open source tool that lets you securely and anonymous ...

CVSS3: 5.4
0%
Низкий
7 дней назад
github логотип
GHSA-v833-3823-cmhp

OnionShare Receive mode writes uploaded files even when file uploads are disabled

CVSS3: 5.4
0%
Низкий
8 дней назад

Уязвимостей на страницу