github ErugoOSS/Erugo v0.2.15
v0.2.15 - Security Release

8 hours ago

Security Release

This release fixes critical path traversal vulnerabilities that could allow authenticated users to write files to arbitrary locations on the server, leading to Remote Code Execution (RCE).

Security Fixes

  • UploadsController: Sanitize filePaths input and validate resolved paths stay within share directory
  • TusdHooksController: Sanitize bundle manifest paths and validate extraction paths
  • EmailTemplatesController: Validate template IDs to prevent path traversal

Security Advisory

Upgrade Instructions

All users running Erugo v0.2.14 or earlier should upgrade immediately.

Credits

Thanks to Leon Phan of AWARE7 GmbH for responsibly disclosing this vulnerability.

Don't miss a new Erugo release

NewReleases is sending notifications on new releases.