Remote Code Execution Vulnerability in Halo Software by Halo Dev
CVE-2026-67920
Currently unrated
What is CVE-2026-67920?
A vulnerability in Halo version 2.25.4 enables remote attackers to exploit certain components, specifically the MigrationServiceImpl.restoreWorkdir() and org.springframework.util.FileSystemUtils.copyRecursively(), to execute arbitrary code. This security flaw allows unauthorized users to manipulate sensitive data and compromise the integrity of the application, making it critical for users to update to the latest version to mitigate potential risks.
