PatchSiren

halo-dev CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM halo-dev CVE published 2026-09-15

CVE-2026-91772

CVE-2026-91772 is a medium-severity open redirect vulnerability in Halo through version 2.26.1. The vulnerability exists in the anonymous thumbnail endpoint, which fails to validate the URI query parameter. This allows attackers to craft malicious links on the trusted Halo domain that redirect visitors to arbitrary external sites, enabling phishing attacks and abuse of redirect-based trust relationships.

MEDIUM halo-dev CVE published 2026-09-08

CVE-2026-78971

CVE-2026-78971 is a vulnerability in Halo plugin management that allows users to install malicious plugins, potentially enabling attackers to execute commands with Halo process permissions. This vulnerability affects Halo versions <= 2.25.4 and could allow attackers to execute any command with Halo process permissions. Defenders should assess exposure and prioritize verification of plugin management confi [truncated]

CRITICAL halo-dev CVE published 2026-08-18

CVE-2026-67921

A Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4, located in the CorsConfigurer.java and CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code, with a CVSS score of 9.3 indicating CRITICAL severity. Administrators and users of affected versions should be aware and take necessary mitigation actions. The CVE record was published on [truncated]

CRITICAL halo-dev CVE published 2026-08-17

CVE-2026-67919

A critical vulnerability in Halo 2.25.4 allows remote attackers to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components. Defenders should assess exposure, prioritize remediation, and verify affected versions to prevent exploitation and minimize potential damage. This vulnerability has a CVSS score of 9.8, indicating critical sever [truncated]

LOW halo-dev CVE published 2026-07-18

CVE-2026-16088

A path traversal vulnerability was detected in halo-dev halo up to 2.24.2. The vulnerability affects the function Download of the file MigrationEndpoint.java of the component Files Backup Endpoint. This could allow a remote attacker to perform path traversal. The exploit is now public and may be used. The CVSS score is 2, with a severity of LOW. Users of halo-dev halo up to 2.24.2 should assess the vulner [truncated]

LOW halo-dev CVE published 2026-07-10

CVE-2026-15326

A path traversal vulnerability was identified in Halo-Dev Halo up to 2.24.2. The vulnerability affects the Theme Installation component, specifically the ThemeUtils.unzipThemeTo function in ThemeUtils.java. The issue allows for path traversal through manipulation of the metadata.name argument. The attack may be launched remotely. The project closed the issue as 'duplicate' but did not reference any other [truncated]