PT-2026-99363 · Hugo · Hugo

·

CVE-2026-100692

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hugo versions 0.123.1 through 0.165.x
Description Symlink confinement checks in the static site generator stop at the mount root. This allows a theme or vendored module located in themes/ to contain a symlink at a mount root (e.g., themes/mytheme/assets pointing to /some/dir/outside). Files behind such symlinks can be read during a site build using functions such as resources.Get() and resources.Match(), and may be published to the public/ directory via static mounts. This bypasses the requirement that theme and module mount sources must be local paths. Modules fetched via Go modules are not affected as their zip files cannot contain symlinks.
Recommendations Update to version 0.166.0. Inspect themes/ and vendored modules for symlinks at mount roots before building. Replace symlinks with explicit mounts.

Exploit

Fix

DoS

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100692
GHSA-797M-7J5G-3RPR

Affected Products

Hugo