CVE-2026-91772

Summary

Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious links on the trusted Halo domain that redirect visitors to arbitrary external sites, enabling phishing attacks and abuse of redirect-based trust relationships.

Affected Software

VendorProductVersion RangeStatus
halo-devhalo0 <= 2.26.1affected

Weaknesses

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

References