OnionShare 2.6.3 Vulnerability: Symlink Following Risk
OnionShare versions 2.6.3 (CLI and Desktop) appear to follow symbolic links in shared directories, which may allow unintended disclosure of local files. Users sharing directories with untrusted symlinks are reportedly at risk.
What happened
OnionShare 2.6.3 (both CLI and Desktop versions) is under investigation for a vulnerability where it follows symbolic links within shared directories. This behavior may allow a remote recipient with access to the OnionShare service to read arbitrary local files that the symlink points to, if those files are readable by the OnionShare process.
The vulnerability is tracked under GHSA-22P9-R2F5-22MF. The recommended action is to avoid sharing directories that contain untrusted symlinks until a patched version of OnionShare is released. For more detailed information, consult the primary source at https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf.
Professional software engineers assessing their exposure should review their use of OnionShare and identify any instances where directories with untrusted symlinks are shared. It is advised to stay updated with the OnionShare project for any patches or further advisories.
How 0Day mitigates this
onionshare-cli is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.