CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.1. See the original NVD description below for full technical details.
CVE
CVE-2025-44594
Severity
CRITICAL
CVSS
9.1
EPSS
0.35%
Original NVD Description
halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.
Related CVEs
Other vulnerabilities affecting the same vendor(s)