Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100694— Hugo before 0.166.0 Cross-Site Scripting via text/org

Quick assessment

Affected
gohugoio hugo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Hugo 是一个静态网站生成器。在 v0.56.0 至 v0.165.x 版本中,映射到 text/org 媒体类型的内容文件在未对原始 HTML 进行转义的情况下被渲染:Org 导出块和 @@html:...@@ 片段会未经转义地传递 HTML 代码,从而导致生成网站中出现跨站脚本攻击(XSS)。如果攻击者能够提供或影响位于 /content 目录下的内容文件,或者影响内容适配器(content adapter)的输出,便可以向受影响页面的访问者浏览器中注入并执行恶意脚本。仅当源文件或内容适配器输出声明使用 te

CVSS 6.1 · Medium EPSS 0.19% · P8

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100694

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hugo before 0.166.0 Cross-Site Scripting via text/org
Source: CVE Program / CVE List V5
Vulnerability Description
Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through unescaped, resulting in cross-site scripting (XSS) in the generated site. An attacker who can supply or influence a content file under /content or the output of a content adapter can inject scripts that execute in the browsers of visitors to the affected pages. Only pages whose source file or content-adapter output declares the text/org media type are affected, and sites that fully trust all content sources are not impacted. Version v0.166.0 fixes the issue by introducing a security.allowContent allowlist that denies text/org by default; sites that intentionally author Org Mode content can opt back in with [security] allowContent = ['.*'].
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
gohugoio hugo 0.56.0 ~ 0.166.0 -

II. Public POCs for CVE-2026-100694

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100694

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100694 (1)

Other References for CVE-2026-100694 (1)

Same Patch Batch · gohugoio · 2026-09-26 · 5 CVEs total

CVE-2026-100693 8.4 HIGH Hugo v0.162.0 before v0.166.0 IP-literal Deny Rule Bypass
CVE-2026-100690 7.5 HIGH Hugo v0.161.0 to v0.165.0 Arbitrary File Read via Symlinks
CVE-2026-100692 7.5 HIGH Hugo before v0.166.0 Path Traversal via Symlinked Mount Roots
CVE-2026-100691 5.4 MEDIUM Hugo before 0.166.0 Stored XSS via lineAnchors code block option

IV. Related Vulnerabilities

V. Comments for CVE-2026-100694

No comments yet


Leave a comment