Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

hugo — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in hugo, with AI-generated Chinese analysis, references, and POCs.

This page catalogs vulnerabilities associated with Hugo, a popular static site generator, categorized under general software weakness types. The aggregation compiles security incidents affecting the Hugo product ecosystem, covering the time range from early 2018 through the current year, ensuring a comprehensive historical perspective on the tool's security landscape. Users can track vendor advisories issued by the Hugo project maintainers to stay informed about critical patches and mitigation strategies. Additionally, the page provides detailed insights into specific weakness classes exploited in past incidents, such as cross-site scripting or path traversal, allowing developers to understand common attack vectors. Readers can also look up a product's vulnerability history to assess long-term security trends and the frequency of reported issues over time. This resource is designed for security professionals, developers, and auditors who need accurate, consolidated data to evaluate risks, perform impact analysis, and implement robust security controls within their Hugo-based infrastructure. By centralizing this information, the page facilitates informed decision-making regarding upgrades, configuration hardening, and third-party dependency management. It serves as a reference point for understanding the evolution of security flaws in Hugo, highlighting both resolved and lingering concerns. The data is structured to support threat modeling and compliance reporting efforts, ensuring that stakeholders have access to verified vulnerability metrics without navigating fragmented sources.

Vendor: gohugoio

CVE ID Title CVSS Severity Published
CVE-2026-89259 Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS CWE-250 9.8 Critical 2026-09-11
CVE-2026-89258 Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get CWE-59 6.3 Medium 2026-09-11
CVE-2026-10582 Hugo 0.91.0 through 0.165.0 Server-Side Request Forgery via security.http.urls Lacking Destination Address Validation CWE-918 7.4 High 2026-08-24
CVE-2026-10618 Hugo 0.93.0 through 0.165.0 Stored Cross-Site Scripting via Unescaped Code-Fence Attribute Values CWE-79 5.4 Medium 2026-08-24
CVE-2026-75926 Hugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process Grant CWE-1188 8.6 High 2026-08-18
CVE-2026-50135 Hugo: Symlink confinement bypass in resources.Get CWE-59 - - 2026-07-06
CVE-2026-50134 Hugo: security.http.urls allow-list bypass via HTTP redirects CWE-918 - - 2026-07-06
CVE-2026-50133 Hugo: XSS via text/html content files CWE-79 - - 2026-07-06
CVE-2026-58403 Hugo symlink confinement bypass in os.ReadFile CWE-59 - - 2026-07-06
CVE-2026-58402 Hugo default code block renderer XSS via unescaped code-fence language CWE-79 - - 2026-07-06
CVE-2026-58404 Hugo security.http.urls deny rules bypassed by alternate IPv4 encodings CWE-918 - - 2026-07-06
CVE-2026-44301 Hugo: Node tool execution allows file system access outside the project directory CWE-22 - - 2026-05-12
CVE-2026-35166 Hugo does not properly escape some Markdown links CWE-79 6.4 - 2026-04-06
CVE-2024-55601 Hugo does not escape some attributes in internal templates CWE-79 5.4 - 2024-12-09
CVE-2024-32875 Hugo doesn't escape markdown title in internal render hooks CWE-80 6.1 Medium 2024-04-23
CVE-2020-26284 Hugo can execute a binary from the current directory on Windows CWE-78 7.7 High 2020-12-21

All 16 known CVE vulnerabilities affecting hugo with full Chinese analysis, references, and POCs where available.