Unclaimed project
Are you a maintainer of Erugo? Claim this project to take control of your public changelog and roadmap.
Changelog
A powerful, self-hosted file-sharing platform built with PHP and Laravel with a Vue.js frontend. It offers secure, customizable file-transfer capabilities through an elegant user interface, giving you complete control over your data while providing a seamless experience for both senders and recipients.
This release fixes critical path traversal vulnerabilities that could allow authenticated users to write files to arbitrary locations on the server, leading to Remote Code Execution (RCE).
filePaths input and validate resolved paths stay within share directoryAll users running Erugo v0.2.14 or earlier should upgrade immediately.
Thanks to Leon Phan of AWARE7 GmbH for responsibly disclosing this vulnerability.