Medium severity6.1NVD Advisory· Published Sep 15, 2026
CVE-2026-91772
CVE-2026-91772
Description
Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious links on the trusted Halo domain that redirect visitors to arbitrary external sites, enabling phishing attacks and abuse of redirect-based trust relationships.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/halo-dev/halo/blob/v2.26.1/application/src/main/java/run/halo/app/core/endpoint/theme/ThumbnailEndpoint.javanvd
- github.com/halo-dev/halo/blob/v2.26.1/application/src/main/resources/extensions/role-template-anonymous.yamlnvd
- github.com/halo-dev/halo/issues/10247nvd
- www.vulncheck.com/advisories/halo-through-2.26.1-open-redirect-via-unvalidated-uri-parameternvd
News mentions
0No linked articles in our index yet.