PT-2026-99361 · Hugo · Hugo
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hugo versions 0.161.0 through 0.165.0
Description
Node.js tools including
css.PostCSS, css.TailwindCSS, and js.Babel are executed under a permission model intended to restrict file system reads to the project directory and configured mounts. However, the model only validates the lexical path and follows symbolic links pointing outside the allowed set, failing to detect symlinks that escape the sandbox. An attacker capable of contributing content to a project can commit a symbolic link pointing to a sensitive file, such as /etc/passwd, combined with a PostCSS plugin to read it. This allows any file readable by the build process to be disclosed and potentially embedded in the published site. This issue affects builds using the default security configuration and does not impact projects that do not use Node.js tools.Recommendations
Update Hugo to version 0.166.0.
As a temporary mitigation, avoid using the
css.PostCSS, css.TailwindCSS, and js.Babel tools.Exploit
Fix
DoS
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hugo