OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality.
https://github.com/advisories/GHSA-7g47-xxff-9p85
https://www.ihteam.net/advisory/onionshare/
https://github.com/onionshare/onionshare/compare/v2.3.3...v2.4