CVE-2026-15326 MEDIUM

CVE-2026-15326: halo-dev halo Theme Installation ThemeUtils.java ThemeUtils.unzipThemeTo path traversal

Vendor Halo-Dev
Product halo
Weakness CWE-22 · Path traversal
Published July 10, 2026
Last update July 10, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the component Theme Installation. Such manipulation of the argument metadata.name leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The project closed the issue as "duplicate" but did not reference any other issue, report, or CVE.

Key dates

02Disclosure timeline

July 10, 2026 CVE published

Related vulnerabilities

04Related CVE