PT-2026-99363 · Hugo · Hugo
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hugo versions 0.123.1 through 0.165.x
Description
Symlink confinement checks in the static site generator stop at the mount root. This allows a theme or vendored module located in
themes/ to contain a symlink at a mount root (e.g., themes/mytheme/assets pointing to /some/dir/outside). Files behind such symlinks can be read during a site build using functions such as resources.Get() and resources.Match(), and may be published to the public/ directory via static mounts. This bypasses the requirement that theme and module mount sources must be local paths. Modules fetched via Go modules are not affected as their zip files cannot contain symlinks.Recommendations
Update to version 0.166.0.
Inspect
themes/ and vendored modules for symlinks at mount roots before building.
Replace symlinks with explicit mounts.Exploit
Fix
DoS
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hugo