gohugoio hugo
7 known vulnerabilities in gohugoio hugo, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-100694 CVSS 5.1 medium Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered…
- CVE-2026-100693 CVSS 8.6 high Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that…
- CVE-2026-100692 CVSS 8.7 high Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount…
- CVE-2026-100691 CVSS 5.1 medium Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the…
- CVE-2026-100690 CVSS 8.7 high Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model…
- CVE-2026-89259 CVSS 9.3 critical Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the…
- CVE-2026-89258 CVSS 9.3 critical Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during…