PT-2026-99365 · Hugo · Hugo
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Hugo versions 0.56.0 through 0.165.x
Description
Content files mapped to the
text/org media type are rendered without escaping raw HTML. Specifically, Org export blocks and @@html:...@@ snippets allow HTML to pass through unescaped, leading to cross-site scripting (XSS) in the generated site. An attacker capable of supplying or influencing a content file under /content or the output of a content adapter can inject scripts that execute in the browsers of visitors. This issue only affects pages where the source file or content-adapter output declares the text/org media type.Recommendations
Update to version 0.166.0 or later.
For sites that intentionally author Org Mode content, enable the feature by setting
[security] allowContent = ['.*'] in the configuration.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hugo