Junglewise Threat Intelligence

CVE-2026-91772: Halo open redirect vulnerability in thumbnail endpoint

CVE-2026-91772 · Severity: medium · CVSS 6.1 · Published 2026-09-15

Technologies: Halo. Vendors: Halo.

Executive brief

Halo is an open-source website builder and blogging platform. The application contains an open redirect flaw in its thumbnail endpoint that fails to validate user-supplied URLs, allowing attackers to craft malicious links that redirect users to arbitrary external websites. This can be exploited for phishing attacks and to abuse the trust placed in the Halo domain itself.

Technical details

The vulnerability is an open redirect in the anonymous thumbnail endpoint (/thumbnails/-/via-uri) that fails to properly validate the uri query parameter. Attackers can craft a specially designed URL on a trusted Halo instance that redirects visitors to attacker-controlled external sites without warning. The flaw exists because input validation is insufficient when processing user-controlled URI parameters. No authentication is required to exploit this vulnerability as the endpoint is anonymously accessible. While this enables phishing and trust abuse, no direct code execution or data breach occurs. A patch is expected to be available in a version after 2.26.1.

Affected products

  • Halo Halo through 2.26.1

Timeline

  • 2026-09-15: disclosed

References

Related threats