CVE-2025-44594 | halo up to 2.20.17 upload-from-url server-side request forgery
A vulnerability categorized as critical has been discovered in halo up to 2.20.17. Affected by this vulnerability is an unknown functionality of the file /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url. Executing manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2025-44594. The attack can be launched remotely. No exploit exists.