CVE-2022-21690

HIGH

OnionShare < 2.5 - Stored Cross-Site Scripting via URL Path Parameter

Title source: llm
STIX 2.1

Description

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not sanitized before being passed to the QT frontend. This path is used in all components for displaying the server access history. This leads to a rendered HTML4 Subset (QT RichText editor) in the Onionshare frontend.

References (2)

Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/onionshare/onionshare/releases/tag/v2.5

Scores

CVSS v3 8.7
EPSS 0.0079
EPSS Percentile 52.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
onionshare/onionshare < 2.5
pypi/onionshare-cli 0 - 2.5PyPI
Published Jan 18, 2022
Tracked Since Feb 18, 2026