Hugo · Hugo · CVE-2026-58402
**Name of the Vulnerable Software and Affected Versions**
Hugo versions 0.60.0 through 0.163.2
**Description**
The default code-block renderer fails to perform HTML escaping when writing the Markdown code-fence language or info-string into the `code` element's `class` and `data-lang` attributes. An attacker can provide a fence info-string containing a quote and a script payload to break out of the attribute and inject a live script element into the page.
**Recommendations**
Update to version 0.163.3.