VYPR
Medium severity6.1NVD Advisory· Published Sep 15, 2026

CVE-2026-91772

CVE-2026-91772

Description

Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious links on the trusted Halo domain that redirect visitors to arbitrary external sites, enabling phishing attacks and abuse of redirect-based trust relationships.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Halo Dev/Haloreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=2.26.1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.