Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100691— Hugo before 0.166.0 Stored XSS via lineAnchors code block option

Quick assessment

Affected
gohugoio hugo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Hugo 0.75.0 至 0.165.x 版本中存在一个存储型跨站脚本(XSS)漏洞:语法高亮器在将 选项传递给 Chroma 之前未对其进行转义处理,导致 Chroma 将该值原样写入生成的行号标记的 和 属性中。攻击者通过在 Markdown 代码块属性中构造恶意的 值(或将其传递给 模板函数),可以在渲染后的页面中注入未转义的 HTML,从而导致访问生成网站的用户浏览器中执行任意 JavaScript 代码。 此漏洞主要影响那些从不受信任的贡献者处接收并构建、发布 Markdown 内容的网站;而 Hugo

CVSS 5.4 · Medium EPSS 0.17% · P5
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100691

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hugo before 0.166.0 Stored XSS via lineAnchors code block option
Source: CVE Program / CVE List V5
Vulnerability Description
Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `href` attributes of the generated line-number markup. A crafted `lineAnchors` value supplied as a Markdown code fence attribute (or passed to the `highlight` template function) results in unescaped HTML in the rendered page, allowing arbitrary JavaScript to execute in the browsers of visitors to the generated site. This affects sites that build and publish Markdown from untrusted contributors; Hugo's security model otherwise considers content trusted input. Fixed in 0.166.0, where the `lineAnchors` value is HTML-escaped before being passed to Chroma.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
gohugoio hugo 0.75.0 ~ 0.166.0 -

II. Public POCs for CVE-2026-100691

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100691

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100691 (1)

Other References for CVE-2026-100691 (1)

Same Patch Batch · gohugoio · 2026-09-26 · 5 CVEs total

CVE-2026-100693 8.4 HIGH Hugo v0.162.0 before v0.166.0 IP-literal Deny Rule Bypass
CVE-2026-100690 7.5 HIGH Hugo v0.161.0 to v0.165.0 Arbitrary File Read via Symlinks
CVE-2026-100692 7.5 HIGH Hugo before v0.166.0 Path Traversal via Symlinked Mount Roots
CVE-2026-100694 6.1 MEDIUM Hugo before 0.166.0 Cross-Site Scripting via text/org

IV. Related Vulnerabilities

V. Comments for CVE-2026-100691

No comments yet


Leave a comment