Executive brief
Halo is an open-source website builder and blogging platform. The application contains an open redirect flaw in its thumbnail endpoint that fails to validate user-supplied URLs, allowing attackers to craft malicious links that redirect users to arbitrary external websites. This can be exploited for phishing attacks and to abuse the trust placed in the Halo domain itself.
Technical details
The vulnerability is an open redirect in the anonymous thumbnail endpoint (/thumbnails/-/via-uri) that fails to properly validate the uri query parameter. Attackers can craft a specially designed URL on a trusted Halo instance that redirects visitors to attacker-controlled external sites without warning. The flaw exists because input validation is insufficient when processing user-controlled URI parameters. No authentication is required to exploit this vulnerability as the endpoint is anonymously accessible. While this enables phishing and trust abuse, no direct code execution or data breach occurs. A patch is expected to be available in a version after 2.26.1.
Affected products
- Halo Halo through 2.26.1
Timeline
- 2026-09-15: disclosed