Hugo · Hugo · CVE-2026-100694
**Name of the Vulnerable Software and Affected Versions**
Hugo versions 0.56.0 through 0.165.x
**Description**
Content files mapped to the `text/org` media type are rendered without escaping raw HTML. Specifically, Org export blocks and `@@html:...@@` snippets allow HTML to pass through unescaped, leading to cross-site scripting (XSS) in the generated site. An attacker capable of supplying or influencing a content file under `/content` or the output of a content adapter can inject scripts that execute in the browsers of visitors. This issue only affects pages where the source file or content-adapter output declares the `text/org` media type.
**Recommendations**
Update to version 0.166.0 or later.
For sites that intentionally author Org Mode content, enable the feature by setting `[security] allowContent = ['.*']` in the configuration.