Impact
The vulnerability involves improper neutralization of SpEL expressions within the ReplyNotificationSubscriptionHelper component. Based on the description, it is inferred that maliciously crafted input could lead to the unintended execution of arbitrary code or other unintended operations on the host. The flaw is situated in application/src/main/java/run/halo/app/content/comment/ReplyNotificationSubscriptionHelper.java of the SpEL handler.
Affected Systems
Halo‑dev Halo versions up to and including 2.25.4 and 2.26.1 are vulnerable. The problem is tied to the component SpEL handler located in application/src/main/java/run/halo/app/content/comment; no fixed version is listed, so any release matching or older than those remains at risk until a vendor patch is released.
Risk and Exploitability
The CVSS score of 6.9 rates the vulnerability as moderate and the EPSS score is not available, indicating limited current exploitation data. The vulnerability is not listed in CISA KEV. Since the exploit has been disclosed publicly, the attack could potentially be carried out over the network, though no specific exploitation has been observed.
OpenCVE Enrichment