Halo 2.25.4 contains a remote code execution vulnerability in its plugin installation flow. The issue involves URI-based plugin installation handling and plugin application-context creation, allowing an attacker to cause arbitrary code execution on an affected Halo instance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a working proof-of-concept exploit for CVE-2026-67919 affecting Halo 2.25.4. It is not a scanner or detection script; it builds a malicious PF4J/Halo plugin JAR intended to be installed through Halo's authenticated plugin installation-from-URI feature. The exploit abuses the server-side behavior described in the README: an authenticated administrator submits a remote JAR URL to /apis/api.console.halo.run/v1alpha1/plugins/-/install-from-uri, Halo fetches the JAR without adequate URI/domain or SSRF validation, stores it temporarily, and dynamically loads it into the JVM, resulting in arbitrary code execution. Repository structure is small and purpose-built: README.md documents the vulnerability, attack chain, and exploitation steps; build-plugin.sh compiles stub PF4J/SLF4J/Jakarta annotation classes and packages the malicious plugin into poc-plugin.jar; plugin-src/plugin.yaml is the plugin manifest declaring metadata and the pluginClass; PocPlugin.java implements the PF4J plugin lifecycle and executes a shell command in start(); PocExtension.java defines an @Extension bean whose @PostConstruct method also executes a shell command when Spring initializes the extension. The dual execution paths increase reliability by triggering payload execution either during plugin startup or bean initialization. Main exploit capability: arbitrary OS command execution on the Halo host/container under the Halo process privileges. The included payload is simple and hardcoded: it runs id and whoami, redirecting output to /tmp/halo-poc-pwned.txt, then reads/logs the file contents. The exploit requires valid administrative/plugin-management credentials and outbound network reachability from the target to the attacker-controlled JAR host. The code contains no automated HTTP client to attack Halo directly; instead, it provides the malicious artifact and build tooling, while the README shows the exact API request needed to trigger installation.
Repository contains a working exploit set for Halo plugin-install/upgrade and migration-restore vulnerabilities, plus a malicious plugin payload. The structure is split into: exploit/ (Python and browser exploit clients), plugin/ (Java PF4J-style malicious plugin and build script), and notes/ (research/verification details). Main capabilities are: (1) authenticated admin RCE by POSTing an arbitrary JAR URL to install-from-uri, then enabling the plugin; (2) one-request RCE by upgrading an existing plugin from an attacker-controlled URL with matching metadata.name and higher version; (3) browser-only CSRF/CORS chain that performs the same actions from a victim admin’s browser without XSRF validation; and (4) migration restore abuse that causes Halo to fetch an arbitrary ZIP and restore it, with destructive overwrite effects and write-into-workdir behavior. The Python login helper automates Halo’s login flow by scraping /login for _csrf and the RSA public key, encrypting the password client-side equivalent, then establishing a session. The malicious Java plugin is straightforward and operational: it executes shell commands via sh -c in both a static initializer and a @PostConstruct method, writing proof files under /tmp. The build script fetches PF4J/Jakarta dependencies from Maven Central and packages the plugin with META-INF/plugin-components.idx and plugin.yaml. Overall, this is a real exploit repository, not a detector: it provides end-to-end exploitation for Halo admin-to-RCE and SSRF-like arbitrary fetch primitives, with a destructive migration restore PoC as well.
7 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.