Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100690— Hugo v0.161.0 to v0.165.0 Arbitrary File Read via Symlinks

Quick assessment

Affected
gohugoio hugo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Hugo 版本从 v0.161.0 到 v0.165.0 在执行 Node.js 工具(如 css.PostCSS、css.TailwindCSS、js.Babel)时,依赖 Node.js 的权限模型来限制文件读取范围,仅允许访问项目目录及已配置的挂载点。然而,Node.js 权限模型仅对字面路径进行验证,并会跟随指向允许范围之外的符号链接,导致 Hugo 无法检测到绕过沙箱的符号链接。如果攻击者能够向 Hugo 项目贡献内容(例如通过拉取请求),他们可以将一个指向敏感文件(如 assets/css/x.css

CVSS 7.5 · High EPSS 0.35% · P26

Possible ATT&CK Techniques 1 AI

T1083 · File and Directory Discovery
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100690

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hugo v0.161.0 to v0.165.0 Arbitrary File Read via Symlinks
Source: CVE Program / CVE List V5
Vulnerability Description
Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox. An attacker who can contribute content to a Hugo project (for example via a pull request) can commit a symlink such as assets/css/x.css -> /etc/passwd together with a PostCSS plugin that reads it, allowing any file readable by the Hugo build process to be disclosed and potentially embedded in the published site. This affects builds using the default security configuration; projects that do not invoke Node.js tools are unaffected. Fixed in v0.166.0, which scans allowed paths and fails the build when a symbolic link resolves outside them.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
gohugoio hugo 0.161.0 ~ 0.166.0 -

II. Public POCs for CVE-2026-100690

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100690

请登录查看更多情报信息。

News Coverage for CVE-2026-100690 (1)

Other References for CVE-2026-100690 (1)

Same Patch Batch · gohugoio · 2026-09-26 · 5 CVEs total

CVE-2026-100693 8.4 HIGH Hugo v0.162.0 before v0.166.0 IP-literal Deny Rule Bypass
CVE-2026-100692 7.5 HIGH Hugo before v0.166.0 Path Traversal via Symlinked Mount Roots
CVE-2026-100694 6.1 MEDIUM Hugo before 0.166.0 Cross-Site Scripting via text/org
CVE-2026-100691 5.4 MEDIUM Hugo before 0.166.0 Stored XSS via lineAnchors code block option

IV. Related Vulnerabilities

V. Comments for CVE-2026-100690

No comments yet


Leave a comment