CVE-2025-44594
CRITICALCVSS 9.1/10EPSS 0.35%
Last modified
CVE-2025-44594 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Halo | Halo | <= 2.20.17 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-44594?
halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.
How severe is CVE-2025-44594?
CVE-2025-44594 has a CVSS score of 9.1/10 (CRITICAL severity). The EPSS model estimates a 0.35% probability of exploitation in the next 30 days.
How do I fix CVE-2025-44594?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4456A vulnerability classified as critical has been found in Pro…9.8
- CVE-2025-44560owntone-server 2ca10d9 is vulnerable to Buffer Overflow due …9.8
- CVE-2025-4457A vulnerability classified as critical was found in Project …9.8
- CVE-2025-4458A vulnerability was found in code-projects Patient Record Ma…8.8
- CVE-2025-4459A vulnerability was found in code-projects Patient Record Ma…8.8
- CVE-2025-44593Halo prior to 2.20.13 allows bypassing file type detection a…6.1
- CVE-2025-44595Halo v2.20.17 and before is vulnerable to Cross Site Scripti…6.1
- CVE-2025-4460A vulnerability classified as problematic has been found in …4.8
- CVE-2025-44608CloudClassroom-PHP Project v1.0 was discovered to contain a …6.5
- CVE-2025-4461A vulnerability classified as problematic was found in TOTOL…5.4
- CVE-2025-44612Tinxy WiFi Lock Controller v1 RF was discovered to transmit …5.9
- CVE-2025-44614Tinxy WiFi Lock Controller v1 RF was discovered to store use…7.5
Are you affected by CVE-2025-44594?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
