github.com/gohugoio/hugo
The world’s fastest framework for building websites.
Activity
- Latest release
- Jun 08, 2026
- Total releases
- 50
- Cadence
- ~2 months
- Last 12 months
- 8
Reach
- Stars
- 89.2k
Details
- First release
- Apr 24, 2017
| Version | Released | |
|---|---|---|
v0.163.0
minor
3 CVEs
CVE-2026-58404
GO-2026-5606
GHSA-r46f-3rpw-hxrv
Jul 24, 2026
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) in github.com/gohugoio/hugo Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev |
v0.163.0
minor
Dependencies (80)
+ 72 more |
|
v0.162.1
minor
3 CVEs
CVE-2026-58404
GO-2026-5606
GHSA-r46f-3rpw-hxrv
Jul 24, 2026
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) in github.com/gohugoio/hugo Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev |
v0.162.1
minor
Dependencies (80)
+ 72 more |
|
v0.160.1
minor
6 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.160.1
minor
Dependencies (80)
+ 72 more |
|
v0.155.0
minor
7 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.155.0
minor
Dependencies (81)
+ 73 more |
|
v0.154.1
minor
7 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.154.1
minor
Dependencies (81)
+ 73 more |
|
v0.153.2
minor
7 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.153.2
minor
Dependencies (81)
+ 73 more |
|
v0.152.2
minor
7 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.152.2
minor
Dependencies (82)
+ 74 more |
|
v0.151.1
minor
7 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.151.1
minor
Dependencies (84)
+ 76 more |
|
v0.148.1
minor
7 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.148.1
minor
Dependencies (82)
+ 74 more |
|
v0.147.4
minor
7 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.147.4
minor
Dependencies (82)
+ 74 more |
|
v0.146.6
minor
7 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.146.6
minor
Dependencies (82)
+ 74 more |
|
v0.134.1
minor
8 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-55601
GO-2024-3314
GHSA-c2xf-9v2r-r2rx
Dec 10, 2024
Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Fixed in
0.139.4
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.134.1
minor
Dependencies (82)
+ 74 more |
|
v0.133.0
minor
8 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-55601
GO-2024-3314
GHSA-c2xf-9v2r-r2rx
Dec 10, 2024
Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Fixed in
0.139.4
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.133.0
minor
Dependencies (82)
+ 74 more |
|
v0.128.1
minor
8 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-55601
GO-2024-3314
GHSA-c2xf-9v2r-r2rx
Dec 10, 2024
Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Fixed in
0.139.4
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.128.1
minor
Dependencies (80)
+ 72 more |
|
v0.125.5
minor
8 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-55601
GO-2024-3314
GHSA-c2xf-9v2r-r2rx
Dec 10, 2024
Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Fixed in
0.139.4
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.125.5
minor
Dependencies (78)
+ 70 more |
|
v0.123.4
minor
9 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-55601
GO-2024-3314
GHSA-c2xf-9v2r-r2rx
Dec 10, 2024
Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Fixed in
0.139.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32875
GO-2024-2747
GHSA-ppf8-hhpp-f5hj
Jun 04, 2024
Hugo Markdown titles are not escaped in internal render hooks in github.com/gohugoio/hugo Hugo Markdown titles are not escaped in internal render hooks in github.com/gohugoio/hugo Fixed in
0.125.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.123.4
minor
Dependencies (78)
+ 70 more |
|
v0.122.0
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.122.0
minor
Dependencies (76)
+ 68 more |
|
v0.121.2
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.121.2
minor
Dependencies (75)
+ 67 more |
|
v0.120.4
patch
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.120.4
patch
Dependencies (75)
+ 67 more |
|
v0.120.2
patch
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.120.2
patch
Dependencies (75)
+ 67 more |
|
v0.120.1
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.120.1
minor
Dependencies (75)
+ 67 more |
|
v0.118.2
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.118.2
minor
Dependencies (74)
+ 66 more |
|
v0.115.3
patch
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.115.3
patch
Dependencies (74)
+ 66 more |
|
v0.115.2
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.115.2
minor
Dependencies (74)
+ 66 more |
|
v0.112.5
patch
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.112.5
patch
Dependencies (71)
+ 63 more |
|
v0.112.2
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.112.2
minor
Dependencies (71)
+ 63 more |
|
v0.107.0
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.107.0
minor
Dependencies (66)
+ 58 more |
|
v0.104.1
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.104.1
minor
Dependencies (66)
+ 58 more |
|
v0.99.1
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.99.1
minor
Dependencies (66)
+ 58 more |
|
v0.98.0
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.98.0
minor
Dependencies (65)
+ 57 more |
|
v0.95.0
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.95.0
minor
Dependencies (64)
+ 56 more |
|
v0.93.1
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.93.1
minor
Dependencies (64)
+ 56 more |
|
v0.91.2
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.91.2
minor
Dependencies (63)
+ 55 more |
|
v0.89.3
minor
4 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.89.3
minor
Dependencies (62)
+ 54 more |
|
v0.88.0
minor
4 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.88.0
minor
Dependencies (62)
+ 54 more |
|
v0.84.4
patch
4 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.84.4
patch
Dependencies (61)
+ 53 more |
|
v0.84.1
minor
4 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.84.1
minor
Dependencies (61)
+ 53 more |
|
v0.79.0
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.79.0
minor
Dependencies (58)
+ 50 more |
|
v0.77.0
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.77.0
minor
Dependencies (58)
+ 50 more |
|
v0.75.1
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.75.1
minor
Dependencies (56)
+ 48 more |
|
v0.69.2
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.69.2
minor
Dependencies (53)
+ 45 more |
|
v0.67.1
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.67.1
minor
Dependencies (53)
+ 45 more |
|
v0.65.1
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.65.1
minor
Dependencies (53)
+ 45 more |
|
v0.63.0
minor
5 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.63.0
minor
Dependencies (53)
+ 45 more |
|
v0.59.0
minor
3 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.59.0
minor
Dependencies (52)
+ 44 more |
|
v0.58.0
minor
3 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.58.0
minor
Dependencies (51)
+ 43 more |
|
v0.49.1
minor
3 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.49.1
minor
Dependencies (44)
+ 36 more |
|
v0.30.2
patch
3 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.30.2
patch
|
|
v0.30.1
minor
3 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.30.1
minor
|
|
v0.20.3
initial
3 CVEs
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2020-26284
GHSA-8j34-9876-pvfq
Jun 23, 2021
Hugo can execute a binary from the current directory on Windows
7.7
/ 10
High
Network
High
Low
Required
Changed
High
High
None
ImpactHugo depends on Go's Windows users who run PatchesUsers should upgrade to Hugo v0.79.1. Fixed in
0.79.1
References Updated Jul 08, 2026 · Source: OSV.dev |
v0.20.3
initial
|