Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100692— Hugo before v0.166.0 Path Traversal via Symlinked Mount Roots

Quick assessment

Affected
gohugoio hugo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Hugo 是一个静态网站生成器。在 v0.123.0 之后且 v0.166.0 之前的版本中,Hugo 的符号链接(symlink)限制检查会在挂载根目录(mount root)本身停止。因此,若某个主题(theme)或模块(module)被检出并放置在 目录下(或作为 vendored 模块),其挂载根目录处可能包含一个符号链接(例如: )。在构建网站时,通过 、 等类似函数可以读取位于该符号链接背后的文件,并可通过静态资源挂载(static mounts)将其发布到 目录中,从而绕过“主题和模块的挂载源必须是本

CVSS 7.5 · High EPSS 0.44% · P36

Possible ATT&CK Techniques 1 AI

T1083 · File and Directory Discovery
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100692

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hugo before v0.166.0 Path Traversal via Symlinked Mount Roots
Source: CVE Program / CVE List V5
Vulnerability Description
Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a mount root (for example themes/mytheme/assets -> /some/dir/outside). Files behind such a symlink were readable during a site build through resources.Get, resources.Match and similar functions, and could be published to public/ via static mounts, bypassing the rule that theme and module mount sources must be local paths. Modules fetched via Go modules are not affected because Go module zips cannot contain symlinks, and this is not an escalation for the main project, which may already mount absolute paths by configuration. Fixed in v0.166.0, where symlinked mount roots and symlinked directories between the mount root and the module directory are treated as non-existent for all modules. As a workaround, inspect themes/ and vendored modules for symlinks at mount roots before building, or replace symlinks with explicit mounts.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
gohugoio hugo 0 ~ 0.166.0 -

II. Public POCs for CVE-2026-100692

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100692

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100692 (1)

Other References for CVE-2026-100692 (1)

Same Patch Batch · gohugoio · 2026-09-26 · 5 CVEs total

CVE-2026-100693 8.4 HIGH Hugo v0.162.0 before v0.166.0 IP-literal Deny Rule Bypass
CVE-2026-100690 7.5 HIGH Hugo v0.161.0 to v0.165.0 Arbitrary File Read via Symlinks
CVE-2026-100694 6.1 MEDIUM Hugo before 0.166.0 Cross-Site Scripting via text/org
CVE-2026-100691 5.4 MEDIUM Hugo before 0.166.0 Stored XSS via lineAnchors code block option

IV. Related Vulnerabilities

V. Comments for CVE-2026-100692

No comments yet


Leave a comment