PT-2026-50158 · Hugo · Hugo

CVE-2026-50135

·

Published

2026-06-16

·

Updated

2026-07-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hugo versions 0.123.0 through 0.161.1
Description A regression in the virtual filesystem allows a symlink confinement bypass. The RootMappingFs.statRoot function calls Stat, which follows symlinks, instead of Lstat. This allows a direct lookup via the resources.Get function to follow a symlink pointing outside the mount tree, enabling the reading of arbitrary files accessible to the user running the software. This issue occurs when an attacker can place a symlink inside a mounted directory, such as a locally-vendored theme under themes/.
Recommendations Update to version 0.162.0.

Exploit

Fix

DoS

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50135
GHSA-FW87-FV5R-9FPW
GO-2026-5380
OPENSUSE-SU-2026:21483-1
RHSA-2026:24577

Affected Products

Hugo