Horilla
Open-source HR management system
Horilla shipped six security releases in three weeks, ending with a no-login RCE.
◆Recent moves
- 4d ago
2.1.8 — Security release
The most severe fix in the run: the public recruitment application flow allowed an anonymous visitor to reach code execution. Any self-hosted instance with an internet-facing careers portal needed to patch immediately.
View source ↗ - 21d ago
2.1.5 — Bug-fix release
A short break from security work to fix dashboard cards that spun forever after a filter-set assumption broke eight call sites. It mostly matters to teams that migrated from v1 to v2.
View source ↗ - 22d ago
2.1.4 — Security release
It reopens and properly closes a template-injection hole that an earlier CVE fix had only partly blocked, and fixes a critical API manager check. This is the clearest sign that earlier patches were deny-list band-aids.
View source ↗ - 22d ago
2.1.3 — Security and bug-fix release
Leave approval now needs a second person who actually manages the requester, which closes a self-crediting loophole present in every 2.x release. It also fixes three pages that crashed across 2.1.0 to 2.1.2.
View source ↗ - 23d ago
2.1.2 — Security patch
Three access-control fixes, including one that let any manager rewrite other employees' bank details to redirect salaries. Same root cause as the rest of the run: permission checks scoped too broadly.
View source ↗ - 24d ago
2.1.1 — Security patch
The opening release of the run patches five advisories, including stored XSS that bypassed validation on every REST write and a file read through PDF generation. The scale of it set the tone for the following three weeks.
View source ↗