PT-2026-99361 · Hugo · Hugo

·

CVE-2026-100690

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hugo versions 0.161.0 through 0.165.0
Description Node.js tools including css.PostCSS, css.TailwindCSS, and js.Babel are executed under a permission model intended to restrict file system reads to the project directory and configured mounts. However, the model only validates the lexical path and follows symbolic links pointing outside the allowed set, failing to detect symlinks that escape the sandbox. An attacker capable of contributing content to a project can commit a symbolic link pointing to a sensitive file, such as /etc/passwd, combined with a PostCSS plugin to read it. This allows any file readable by the build process to be disclosed and potentially embedded in the published site. This issue affects builds using the default security configuration and does not impact projects that do not use Node.js tools.
Recommendations Update Hugo to version 0.166.0. As a temporary mitigation, avoid using the css.PostCSS, css.TailwindCSS, and js.Babel tools.

Exploit

Fix

DoS

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100690
GHSA-X3MX-CM49-8M9C
RHSA-2026:66266

Affected Products

Hugo