github.com/gohugoio/hugo
The world’s fastest framework for building websites.
Activity
- Latest release
- 5d ago
- Total releases
- 69
- Cadence
- ~19 days
- Last 12 months
- 27
Reach
- Stars
- 89.8k
Details
- First release
- Apr 24, 2017
| Version | Released | |
|---|---|---|
v0.166.0
minor
|
v0.166.0
minor
Dependencies (80)
+ 72 more |
|
v0.165.0
minor
|
v0.165.0
minor
Dependencies (80)
+ 72 more |
|
v0.164.0
minor
|
v0.164.0
minor
Dependencies (80)
+ 72 more |
|
v0.163.3
patch
|
v0.163.3
patch
Dependencies (80)
+ 72 more |
|
v0.163.2
patch
1 CVE
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev |
v0.163.2
patch
Dependencies (80)
+ 72 more |
|
v0.163.1
patch
1 CVE
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev |
v0.163.1
patch
Dependencies (80)
+ 72 more |
|
v0.163.0
minor
3 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58404
GO-2026-5606
GHSA-r46f-3rpw-hxrv
Jul 24, 2026
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) in github.com/gohugoio/hugo Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v0.163.0
minor
Dependencies (80)
+ 72 more |
|
v0.162.1
minor
3 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58404
GO-2026-5606
GHSA-r46f-3rpw-hxrv
Jul 24, 2026
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) in github.com/gohugoio/hugo Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v0.162.1
minor
Dependencies (80)
+ 72 more |
|
v0.162.0
minor
3 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58404
GO-2026-5606
GHSA-r46f-3rpw-hxrv
Jul 24, 2026
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) in github.com/gohugoio/hugo Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev |
v0.162.0
minor
Dependencies (80)
+ 72 more |
|
v0.161.1
patch
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.161.1
patch
Dependencies (80)
+ 72 more |
|
v0.161.0
minor
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.161.0
minor
Dependencies (80)
+ 72 more |
|
v0.160.1
minor
6 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.160.1
minor
Dependencies (80)
+ 72 more |
|
v0.160.0
minor
6 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.160.0
minor
Dependencies (80)
+ 72 more |
|
v0.159.2
patch
6 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.159.2
patch
Dependencies (80)
+ 72 more |
|
v0.159.1
patch
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.159.1
patch
Dependencies (80)
+ 72 more |
|
v0.159.0
minor
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.159.0
minor
Dependencies (80)
+ 72 more |
|
v0.158.0
minor
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.158.0
minor
Dependencies (80)
+ 72 more |
|
v0.157.0
minor
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.157.0
minor
Dependencies (81)
+ 73 more |
|
v0.156.0
minor
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.156.0
minor
Dependencies (81)
+ 73 more |
|
v0.155.3
patch
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.155.3
patch
Dependencies (81)
+ 73 more |
|
v0.155.2
patch
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.155.2
patch
Dependencies (81)
+ 73 more |
|
v0.155.1
patch
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.155.1
patch
Dependencies (81)
+ 73 more |
|
v0.155.0
minor
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.155.0
minor
Dependencies (81)
+ 73 more |
|
v0.154.1
minor
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.154.1
minor
Dependencies (81)
+ 73 more |
|
v0.153.2
minor
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.153.2
minor
Dependencies (81)
+ 73 more |
|
v0.152.2
minor
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.152.2
minor
Dependencies (82)
+ 74 more |
|
v0.151.1
minor
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.151.1
minor
Dependencies (84)
+ 76 more |
|
v0.148.1
minor
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.148.1
minor
Dependencies (82)
+ 74 more |
|
v0.147.4
minor
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.147.4
minor
Dependencies (82)
+ 74 more |
|
v0.146.6
minor
7 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.146.6
minor
Dependencies (82)
+ 74 more |
|
v0.134.1
minor
8 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-55601
GO-2024-3314
GHSA-c2xf-9v2r-r2rx
Dec 10, 2024
Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Fixed in
0.139.4
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.134.1
minor
Dependencies (82)
+ 74 more |
|
v0.133.0
minor
8 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-55601
GO-2024-3314
GHSA-c2xf-9v2r-r2rx
Dec 10, 2024
Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Fixed in
0.139.4
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.133.0
minor
Dependencies (82)
+ 74 more |
|
v0.128.1
minor
8 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-55601
GO-2024-3314
GHSA-c2xf-9v2r-r2rx
Dec 10, 2024
Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Fixed in
0.139.4
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.128.1
minor
Dependencies (80)
+ 72 more |
|
v0.125.5
minor
8 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-55601
GO-2024-3314
GHSA-c2xf-9v2r-r2rx
Dec 10, 2024
Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Fixed in
0.139.4
References Updated Mar 03, 2026 · Source: OSV.dev |
v0.125.5
minor
Dependencies (78)
+ 70 more |
|
v0.123.4
minor
9 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-58403
GO-2026-5309
GHSA-c3wq-j5vh-68rc
Jul 24, 2026
Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in os.ReadFile in github.com/gohugoio/hugo Fixed in
0.163.1
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50135
GO-2026-5380
GHSA-fw87-fv5r-9fpw
Jul 07, 2026
Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-55601
GO-2024-3314
GHSA-c2xf-9v2r-r2rx
Dec 10, 2024
Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo Fixed in
0.139.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-32875
GO-2024-2747
GHSA-ppf8-hhpp-f5hj
Jun 04, 2024
Hugo Markdown titles are not escaped in internal render hooks in github.com/gohugoio/hugo Hugo Markdown titles are not escaped in internal render hooks in github.com/gohugoio/hugo Fixed in
0.125.3
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.123.4
minor
Dependencies (78)
+ 70 more |
|
v0.122.0
minor
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.122.0
minor
Dependencies (76)
+ 68 more |
|
v0.121.2
minor
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.121.2
minor
Dependencies (75)
+ 67 more |
|
v0.120.4
patch
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.120.4
patch
Dependencies (75)
+ 67 more |
|
v0.120.2
patch
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.120.2
patch
Dependencies (75)
+ 67 more |
|
v0.120.1
minor
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.120.1
minor
Dependencies (75)
+ 67 more |
|
v0.118.2
minor
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.118.2
minor
Dependencies (74)
+ 66 more |
|
v0.115.3
patch
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.115.3
patch
Dependencies (74)
+ 66 more |
|
v0.115.2
minor
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.115.2
minor
Dependencies (74)
+ 66 more |
|
v0.112.5
patch
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.112.5
patch
Dependencies (71)
+ 63 more |
|
v0.112.2
minor
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.112.2
minor
Dependencies (71)
+ 63 more |
|
v0.107.0
minor
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.107.0
minor
Dependencies (66)
+ 58 more |
|
v0.104.1
minor
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.104.1
minor
Dependencies (66)
+ 58 more |
|
v0.99.1
minor
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.99.1
minor
Dependencies (66)
+ 58 more |
|
v0.98.0
minor
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.98.0
minor
Dependencies (65)
+ 57 more |
|
v0.95.0
minor
5 CVEs
CVE-2026-58402
GO-2026-5569
GHSA-q76j-gcg9-vxc6
Jul 24, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Hugo: XSS via unescaped code-fence language in default code block renderer in github.com/gohugoio/hugo Fixed in
0.163.3
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-44301
GO-2026-5740
GHSA-x597-9fr4-5857
Jul 24, 2026
Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo Fixed in
0.161.0
References Updated Jul 24, 2026 · Source: OSV.dev
CVE-2026-35166
GO-2026-5504
GHSA-mcv8-8m8x-48pg
Jul 07, 2026
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo Fixed in
0.159.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50133
GO-2026-5313
GHSA-c54g-xjwj-8g82
Jul 07, 2026
Hugo: XSS via text/html content files in github.com/gohugoio/hugo Hugo: XSS via text/html content files in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-50134
GO-2026-5681
GHSA-vxgm-5rmg-5w8g
Jul 07, 2026
Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo Fixed in
0.162.0
References Updated Jul 07, 2026 · Source: OSV.dev |
v0.95.0
minor
Dependencies (64)
+ 56 more |