Junglewise Threat Intelligence

CVE-2026-15326: halo-dev Halo path traversal in Theme Installation

CVE-2026-15326 · Severity: low · CVSS 3.8 · Published 2026-07-10

Technologies: Halo. Vendors: Halo-Dev, Halo.

Executive brief

A vulnerability was found in Halo, an open-source website builder and content management system. An attacker with administrative privileges can exploit the theme installation process to write files to unintended locations on the server. This could potentially lead to service disruptions or unauthorized modification of system files.

Technical details

A path traversal vulnerability exists in halo-dev Halo up to version 2.24.2 within the Theme Installation component. The root cause is insufficient validation of the 'metadata.name' argument in the ThemeUtils.unzipThemeTo function in ThemeUtils.java. A remote attacker with high privileges (PR:H) can manipulate this argument to escape the intended directory during the theme unzipping process. This can result in arbitrary file writes on the host system. While the project closed the original issue as a duplicate, a public exploit is reportedly available.

Affected products

  • halo-dev Halo up to 2.24.2

Timeline

  • 2026-07-10: disclosed: Vulnerability published to NVD/VulDB

References

Related threats