Impact
The vulnerability exists in Halo versions 2.25.4 and earlier, where the plugin management feature permits users to install or update plugins without sufficient validation. If an attacker can trigger the installation or update process, they can supply a malicious package that is executed with the same permissions as the running Halo process, enabling arbitrary command execution on the host system. The likely attack vector is through the web-based plugin management interface or an exposed API endpoint; based on the description, it is inferred that any authenticated or unauthenticated user who can access that interface could exploit the flaw.
Affected Systems
Halo, all versions 2.25.4 and earlier are affected; no vendor/product version list beyond this is provided in the source data.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity, and the EPSS score of <1% suggests a very low but nonzero probability of exploitation. The flaw is not listed in the CISA KEV catalog, but the ability to execute arbitrary system commands poses a significant confidentiality, integrity, and availability risk. Inferred from the description, attackers could gain system-level compromise by accessing the plugin upload route, pending any authorization controls.
OpenCVE Enrichment