Onionshare is a file-sharing tool designed to facilitate anonymous transfer of files over Tor, and its vulnerability profile centers on a single, narrowly scoped product where exposure recurs through authentication and access-control weaknesses, input-validation issues, and path-traversal conditions. A meaningful share of disclosures reach serious severity; defenders relying on this tool for sensitive data transfer should treat authentication bypasses and directory-traversal flaws as priority risks and track updates accordingly. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Onionshare over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41868CRITICAL OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality. | Oct 4, 2021 | 9.8 | 32 | NO | NO |
CVE-2022-21689HIGH OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions the receive m | Jan 18, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-21693MEDIUM OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions an adversary | Jan 18, 2022 | 6.5 | 22 | NO | NO |
CVE-2018-19960HIGH The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users | Dec 7, 2018 | 7.0 | 21 | NO | NO |
CVE-2022-21694MEDIUM OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare | Jan 18, 2022 | 5.3 | 20 | NO | NO |
CVE-2022-21690MEDIUM OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path para | Jan 18, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-21695MEDIUM OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions authenticated | Jan 18, 2022 | 5.3 | 20 | NO | NO |
CVE-2022-21688MEDIUM OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Affected versions of the desktop a | Jan 18, 2022 | 5.5 | 20 | NO | NO |
CVE-2021-41867MEDIUM An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare no | Oct 4, 2021 | 5.3 | 20 | NO | NO |
CVE-2016-5026MEDIUM hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory. | Jan 30, 2017 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Onionshare.
Media articles that mention a CVE ID that affects a product developed by Onionshare — matched by CVE ID, not by vendor name.