Hugo · Hugo · CVE-2026-100690
**Name of the Vulnerable Software and Affected Versions**
Hugo versions 0.161.0 through 0.165.0
**Description**
Node.js tools including `css.PostCSS`, `css.TailwindCSS`, and `js.Babel` are executed under a permission model intended to restrict file system reads to the project directory and configured mounts. However, the model only validates the lexical path and follows symbolic links pointing outside the allowed set, failing to detect symlinks that escape the sandbox. An attacker capable of contributing content to a project can commit a symbolic link pointing to a sensitive file, such as `/etc/passwd`, combined with a PostCSS plugin to read it. This allows any file readable by the build process to be disclosed and potentially embedded in the published site. This issue affects builds using the default security configuration and does not impact projects that do not use Node.js tools.
**Recommendations**
Update Hugo to version 0.166.0.
As a temporary mitigation, avoid using the `css.PostCSS`, `css.TailwindCSS`, and `js.Babel` tools.