Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-10618— Hugo 0.93.0 through 0.165.0 Stored Cross-Site Scripting via Unescaped Code-Fence Attribute Values

Quick assessment

Affected
gohugoio hugo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Hugo 默认的 fenced-code-block(围栏代码块)渲染器会将来自代码围栏信息字符串(info string)的属性值直接写入渲染后的 HTML,而未经过任何转义处理。在 文件中新增的逻辑,在存储过程中将所有属性值从字节切片(byte slice)转换为字符串,故意丢弃了原本在此处进行的转义操作。同时,同一文件中的 函数仅对仍为字节切片的值进行转义,因此其转义分支实际上永远不会被执行,导致所有属性值均被原样(verbatim)输出。 该函数的文档声称会对字符串类型的属性执行 HTML 转义,但实际并未

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-10618

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Hugo 0.93.0 through 0.165.0 Stored Cross-Site Scripting via Unescaped Code-Fence Attribute Values
Source: CVE Program / CVE List V5
Vulnerability Description
Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a byte slice to a string as it is stored, deliberately dropping the escaping that used to happen there, and RenderAttributes in the same file escapes only values that are still byte slices, so its escaping branch is never reached and every value is written verbatim. The function's documentation states that it performs HTML escaping of string attributes, which it does not. A quote inside an attribute value in the info string therefore terminates the attribute and allows a further attribute, including an event handler, to be placed on the wrapper element, and the script runs for every visitor who loads the page. This path is reached under the default configuration, with code fences enabled and without goldmark's unsafe setting or any custom render hook. Attribute names beginning with on are filtered when the attributes are parsed, so injection is achieved through the value rather than the name.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
gohugoio hugo 0.93.0 ~ 0.165.0 -

II. Public POCs for CVE-2026-10618

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10618

登录查看更多情报信息。

Patches & Fixes for CVE-2026-10618 (2)

Vendor Advisories for CVE-2026-10618 (1)

Vendor Pages for CVE-2026-10618 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-10618

No comments yet


Leave a comment