Impact
Halo, up to version 2.26.1, contains a flaw in the anonymous thumbnail endpoint where the uri query parameter is not validated. This omission allows an attacker to craft a link on the trusted domain that redirects a user to any external URL. The resulting open redirect can be abused for phishing or to steer unsuspecting users to malicious sites, compromising user trust and facilitating credential theft or malware delivery.
Affected Systems
The affected product is halo-dev:halo, specifically all releases up through 2.26.1 that expose the anonymous thumbnail endpoint. Versions later than 2.26.1 are not listed as impacted.
Risk and Exploitability
The vulnerability is straightforward to exploit: a victim clicks a specially crafted link on the same domain and is redirected to an attacker‑chosen site. The CVSS score of 5.3 denotes moderate severity. The EPSS score of <1% indicates a very low current exploitation probability, and the issue is not listed in CISA’s KEV catalog. Nonetheless, because it is accessible to all visitors, the potential for abuse remains high if attackers distribute malicious links via social media or other channels.
OpenCVE Enrichment