PT-2026-5235 · Erugo · Erugo

Leon-Aware7

·

Publicado

2026-01-28

·

Atualizado

2026-02-09

·

CVE-2026-24897

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Erugo versions up to and including 0.2.14
Description Erugo is a self-hosted file-sharing platform. An authenticated, low-privileged user can upload arbitrary files to any specified location due to insufficient validation of user-supplied paths when creating shares. By specifying a writable path within the public web root, an attacker can upload and execute arbitrary code on the server, resulting in remote code execution (RCE). This allows a low-privileged user to fully compromise the affected Erugo instance. The vulnerability is triggered through insufficient validation of paths used when creating shares. The vulnerable component allows attackers to upload files to arbitrary locations, potentially leading to the execution of malicious code.
Recommendations Versions prior to 0.2.15 are affected. Update to version 0.2.15 to address the vulnerability.

Exploit

Correção

RCE

Path traversal

Code Injection

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05160
CVE-2026-24897
GHSA-336W-HGPQ-6369

Produtos afetados

Erugo