CVE-2026-100694
- EPSS 0.19%
- Veröffentlicht 26.09.2026 13:23:52
- Zuletzt bearbeitet 30.09.2026 16:17:00
Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through unescaped, resulting in ...
CVE-2026-100693
- EPSS 0.13%
- Veröffentlicht 26.09.2026 13:23:51
- Zuletzt bearbeitet 30.09.2026 18:18:01
Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to...
CVE-2026-100692
- EPSS 0.44%
- Veröffentlicht 26.09.2026 13:23:50
- Zuletzt bearbeitet 29.09.2026 19:08:03
Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a mount r...
CVE-2026-100691
- EPSS 0.17%
- Veröffentlicht 26.09.2026 13:23:50
- Zuletzt bearbeitet 29.09.2026 19:08:14
Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `href` attributes...
CVE-2026-100690
- EPSS 0.35%
- Veröffentlicht 26.09.2026 13:23:49
- Zuletzt bearbeitet 30.09.2026 16:17:00
Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission mo...
CVE-2026-89259
- EPSS 0.41%
- Veröffentlicht 11.09.2026 11:15:35
- Zuletzt bearbeitet 24.09.2026 20:43:32
Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-pro...
CVE-2026-89258
- EPSS 0.32%
- Veröffentlicht 11.09.2026 11:15:34
- Zuletzt bearbeitet 11.09.2026 15:21:12
Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place — or who convinces a ...
CVE-2026-10618
- EPSS 0.22%
- Veröffentlicht 24.08.2026 11:16:38
- Zuletzt bearbeitet 29.09.2026 19:13:14
Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a byte slice to ...
CVE-2026-10582
- EPSS 0.32%
- Veröffentlicht 24.08.2026 11:16:38
- Zuletzt bearbeitet 24.09.2026 20:43:32
Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-chec...
CVE-2026-75926
- EPSS 0.15%
- Veröffentlicht 18.08.2026 15:47:49
- Zuletzt bearbeitet 29.09.2026 21:03:08
Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory. Hugo 0.162.0 added tailwindcss to the AllowChi...