gohugo

5 records · 5 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names gohugo as an affected vendor, highest CVSS first.

  1. HIGH 8.4CVE-2026-100693public PoC

    Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch fro…

    hugo

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-100692public PoC

    Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a mount root (for e…

    hugo

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-100690public PoC

    Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model valida…

    hugo

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 6.1CVE-2026-100694public PoC

    Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through unescaped, resulting in cross-site…

    hugo

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 5.4CVE-2026-100691public PoC

    Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `href` attributes of the ge…

    hugo

    AI risk analysis on Exploit-DB.ai →