Executive brief
Halo, an open-source website building and content management platform, is affected by a security vulnerability in its attachment handling system. An attacker could potentially inject malicious scripts into the platform, which would then execute in the browser of other users or administrators who view the affected content. This could lead to unauthorized actions being performed on behalf of users, session hijacking, or the defacement of the website.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Halo v.2.20.18LTS and earlier versions within the AttachmentReconciler class. The flaw is located in the reconcile method, which fails to properly neutralize user-supplied input during the attachment reconciliation process. An unauthenticated remote attacker can exploit this by uploading a malicious file or providing crafted input that triggers the execution of arbitrary JavaScript in the context of a victim's browser session. This is a reflected or stored XSS (depending on the reconciliation flow) requiring minimal user interaction to execute.
Affected products
- halo-dev Halo v.2.20.18LTS and before
Timeline
- 2025-08-04: disclosed: Initial researcher gist published
- 2025-08-05: advisory: CVE published to NVD