VDB
Sign up
CRITICAL9.8

PYSEC-2026-434

Remote unauthenticated attackers able to upload files in Onionshare

Quick fix

PYSEC-2026-434 — onionshare-cli: upgrade to the fixed version with the command below.

pip install --upgrade 'onionshare-cli>=2.4'

Details

OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/onionshare-cli
Introduced in: 2.3Fixed in: 2.4
Fixpip install --upgrade 'onionshare-cli>=2.4'

References