PYPI · JULY 2026 · EARLY WARNING

OnionShare 2.6.3 Vulnerability: Symlink Following Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-22P9-R2F5-22MFSeverity: HIGH

OnionShare versions 2.6.3 (CLI and Desktop) appear to follow symbolic links in shared directories, which may allow unintended disclosure of local files. Users sharing directories with untrusted symlinks are reportedly at risk.

What happened

OnionShare 2.6.3 (both CLI and Desktop versions) is under investigation for a vulnerability where it follows symbolic links within shared directories. This behavior may allow a remote recipient with access to the OnionShare service to read arbitrary local files that the symlink points to, if those files are readable by the OnionShare process.

The vulnerability is tracked under GHSA-22P9-R2F5-22MF. The recommended action is to avoid sharing directories that contain untrusted symlinks until a patched version of OnionShare is released. For more detailed information, consult the primary source at https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf.

Professional software engineers assessing their exposure should review their use of OnionShare and identify any instances where directories with untrusted symlinks are shared. It is advised to stay updated with the OnionShare project for any patches or further advisories.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If onionshare-cli is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats