CVE-2026-67920: Halo 2.25.4 vulnerability
Published Aug 18, 2026
·Updated
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components
Affected Software
2 affected components
Halo 2.25.4=2.25.4
Spring Framework org.springframework.util.FileSystemUtils
Event History
Aug 18, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which product versions are confirmed to be affected?
The affected software identified in the available data is Halo 2.25.4. No affected version range or fixed version is provided.
2
What level of access does an attacker need?
The issue is described as remotely exploitable. The available data does not state whether authentication, a particular role, or any specific configuration is required.