Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Bacu79

#33303of 56,330
8.1Total CVSS
Vulnerabilities · 1
PT-2026-38298
8.1
2026-05-06
Hugo · Hugo · CVE-2026-44301
**Name of the Vulnerable Software and Affected Versions** Hugo versions prior to 0.161.0 **Description** When building a site that utilizes Node-based asset pipelines such as PostCSS, Babel, or TailwindCSS, the software invokes configured Node tools without restrictions on file system access. This allows code executed through these tools to read or write files outside the project's working directory when processing an untrusted site. **Recommendations** Update to version 0.161.0 or later. As a temporary workaround, block the affected tools in the `security.exec.allow` configuration.