VDB
Sign up
—

PYSEC-2026-696

Information disclosure vulnerability in OnionShare

Quick fix

PYSEC-2026-696 — onionshare-cli: upgrade to the fixed version with the command below.

pip install --upgrade 'onionshare-cli>=2.4'

Details

An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/onionshare-cli
Introduced in: 2.3Fixed in: 2.4
Fixpip install --upgrade 'onionshare-cli>=2.4'

References