An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.
https://notes.sjtu.edu.cn/s/s5oEvs-p5
https://github.com/halo-dev/halo
https://gist.github.com/b33t1e/a1a0d81b1173d0d00de8f4e7958dd867