Server-Side Request Forgery in Halo Application by Halo Dev
CVE-2026-36757
4.3MEDIUM
What is CVE-2026-36757?
A vulnerability exists in the Halo application version 2.22.14 that enables authenticated attackers to execute Server-Side Request Forgery (SSRF) attacks via the /plugins/{name}/upgrade-from-uri endpoint. By crafting a GET request, attackers can potentially access and scan internal resources, raising significant security concerns for affected systems.
