Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Philipdissert

#46543of 57,410
6.1Total CVSS
Vulnerabilities · 1
PT-2026-99365
6.1
2026-09-26
Hugo · Hugo · CVE-2026-100694
**Name of the Vulnerable Software and Affected Versions** Hugo versions 0.56.0 through 0.165.x **Description** Content files mapped to the `text/org` media type are rendered without escaping raw HTML. Specifically, Org export blocks and `@@html:...@@` snippets allow HTML to pass through unescaped, leading to cross-site scripting (XSS) in the generated site. An attacker capable of supplying or influencing a content file under `/content` or the output of a content adapter can inject scripts that execute in the browsers of visitors. This issue only affects pages where the source file or content-adapter output declares the `text/org` media type. **Recommendations** Update to version 0.166.0 or later. For sites that intentionally author Org Mode content, enable the feature by setting `[security] allowContent = ['.*']` in the configuration.