← Back to all sparks
H

Horilla

HR
Velocity5.0

Open-source HR management system

Horilla shipped six security releases in three weeks, ending with a no-login RCE.

securityaccess-controlopen-sourcehr-softwareself-hosted
◆Current state
Horilla's 2.1.x line has become a running security audit. Between 2.1.1 and 2.1.8 the team closed more than a dozen externally reported advisories, from stored XSS and local file reads to salary-redirect and self-approval flaws, capped by an unauthenticated remote code execution in the public recruitment flow.
◆Where it's heading
The pattern is consistent: outside researchers are probing the 2.x codebase, and the maintainers are responding fast with detailed advisories and no-migration patches. Most of the flaws are authorization checks that trusted any manager relationship rather than the specific record, which points to a codebase-wide access-control review rather than one-off fixes.
◆Prediction
Expect more point releases closing authorization bugs in the remaining HR modules (payroll, attendance, assets) before any feature work resumes on 2.2.

◆Recent moves

  1. 4d ago

    2.1.8 — Security release

    The most severe fix in the run: the public recruitment application flow allowed an anonymous visitor to reach code execution. Any self-hosted instance with an internet-facing careers portal needed to patch immediately.

    View source ↗
  2. 21d ago

    2.1.5 — Bug-fix release

    A short break from security work to fix dashboard cards that spun forever after a filter-set assumption broke eight call sites. It mostly matters to teams that migrated from v1 to v2.

    View source ↗
  3. 22d ago

    2.1.4 — Security release

    It reopens and properly closes a template-injection hole that an earlier CVE fix had only partly blocked, and fixes a critical API manager check. This is the clearest sign that earlier patches were deny-list band-aids.

    View source ↗
  4. 22d ago

    2.1.3 — Security and bug-fix release

    Leave approval now needs a second person who actually manages the requester, which closes a self-crediting loophole present in every 2.x release. It also fixes three pages that crashed across 2.1.0 to 2.1.2.

    View source ↗
  5. 23d ago

    2.1.2 — Security patch

    Three access-control fixes, including one that let any manager rewrite other employees' bank details to redirect salaries. Same root cause as the rest of the run: permission checks scoped too broadly.

    View source ↗
  6. 24d ago

    2.1.1 — Security patch

    The opening release of the run patches five advisories, including stored XSS that bypassed validation on every REST write and a file read through PDF generation. The scale of it set the tone for the following three weeks.

    View source ↗