CVEFind.com@CveFindComPatch
The tweet alerts to a critical RCE flaw in Erugo file-sharing platform versions up to 0.2.14 and recommends upgrading to v0.2.15 to mitigate the threat.
PulsePatch.io@pulsepatchioPatch
An authenticated remote code execution vulnerability via arbitrary file upload has been disclosed for Erugo (CVE‑2026‑24897), and a remediation update is available.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces CVE‑2026‑24897, an authenticated path traversal flaw in the Erugo file‑sharing platform that can lead to remote code execution, but it provides no details about exploits, patches, or active attacks.
The Hacker Wire@TheHackerWireDisclosure
The post discloses that Erugo 0.2.14 allows low‑privileged users to upload arbitrary files, a critical path‑traversal flaw.
CVE@CVEnewDisclosure
CVE-2026-24897 identifies an authenticated low‑privileged file upload vulnerability in Erugo up to version 0.2.14, allowing users to upload arbitrary files to specified locations. No PoC, exploit code, or patch information is provided.
0day Signal@0dayPublishingDisclosure
The post discloses a path traversal vulnerability (CVE-2026-24897) in Erugo that allows authenticated users to upload files to the web root, leading to trivial remote code execution; a PoC link is provided.