CVE-2026-67920 is a remote code execution vulnerability affecting Halo 2.25.4. The issue is associated with the migration restore workflow, specifically the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir() method and its use of org.springframework.util.FileSystemUtils.copyRecursively(). The available information indicates that unsafe handling of files or paths during restoration can allow an attacker to introduce or place attacker-controlled content in a way that results in arbitrary code execution on the target Halo instance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
The repository has two files: a detailed Markdown disclosure and one Python 3 generator, generate-malicious-backup.py. The generator does not contact a target itself; it creates a ZIP archive for manual authenticated upload to Halo's restoration API. It writes a newline-only extensions.data entry and injects attacker-controlled content below workdir/, matching the repository's claim that Halo CMS restore processing recursively copies workdir/ to ~/.halo2/. CLI modes create a marker-file PoC by default, embed a local JAR as plugins/malicious-plugin.jar, generate a 4096-bit RSA keypair for keys/pat_id_rsa and keys/pat_id_rsa.pub, or add a user-defined path/content pair. The README attributes the issue to Halo MigrationServiceImpl.restoreWorkdir() and describes potential plugin replacement for RCE and key replacement for authentication bypass. No concrete CVE has been assigned in the supplied material (it uses CVE-XXXX-XXXXX), and the repository provides no automated upload client or independent validation of the underlying server-side flaw.
Repository contains a working exploit set for Halo plugin-install/upgrade and migration-restore vulnerabilities, plus a malicious plugin payload. The structure is split into: exploit/ (Python and browser exploit clients), plugin/ (Java PF4J-style malicious plugin and build script), and notes/ (research/verification details). Main capabilities are: (1) authenticated admin RCE by POSTing an arbitrary JAR URL to install-from-uri, then enabling the plugin; (2) one-request RCE by upgrading an existing plugin from an attacker-controlled URL with matching metadata.name and higher version; (3) browser-only CSRF/CORS chain that performs the same actions from a victim admin’s browser without XSRF validation; and (4) migration restore abuse that causes Halo to fetch an arbitrary ZIP and restore it, with destructive overwrite effects and write-into-workdir behavior. The Python login helper automates Halo’s login flow by scraping /login for _csrf and the RSA public key, encrypting the password client-side equivalent, then establishing a session. The malicious Java plugin is straightforward and operational: it executes shell commands via sh -c in both a static initializer and a @PostConstruct method, writing proof files under /tmp. The build script fetches PF4J/Jakarta dependencies from Maven Central and packages the plugin with META-INF/plugin-components.idx and plugin.yaml. Overall, this is a real exploit repository, not a detector: it provides end-to-end exploitation for Halo admin-to-RCE and SSRF-like arbitrary fetch primitives, with a destructive migration restore PoC as well.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.