CVE-2026-67920
HIGH 8.8EPSS 0.7%
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.65% chance of exploitation in the next 30 days, 49th percentile
- Published
- 2026-08-18
- Updated
- 2026-08-20
Proof-of-concept exploits (2)
- unpredictable21/halo-2.25.4-backup-write-CVE-2026-679200★ · 2026-07-10
- k0nnect/halo-cve-2026-679191★ · 2026-08-19