Hugo 在 v0.162.0 到 v0.166.0(不含)版本之间,存在一个与安全策略中 的 IP 字面量(IP-literal)拒绝规则相关的区分大小写的验证缺陷。攻击者可以利用此缺陷绕过相关限制,通过在 调用中使用大小写混合的 URL 方案,从受限制的本机地址(如 localhost)获取资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100690 | 7.5 HIGH | Hugo v0.161.0 to v0.165.0 Arbitrary File Read via Symlinks |
| CVE-2026-100692 | 7.5 HIGH | Hugo before v0.166.0 Path Traversal via Symlinked Mount Roots |
| CVE-2026-100694 | 6.1 MEDIUM | Hugo before 0.166.0 Cross-Site Scripting via text/org |
| CVE-2026-100691 | 5.4 MEDIUM | Hugo before 0.166.0 Stored XSS via lineAnchors code block option |
No comments yet