PT-2026-99365 · Hugo · Hugo

·

CVE-2026-100694

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hugo versions 0.56.0 through 0.165.x
Description Content files mapped to the text/org media type are rendered without escaping raw HTML. Specifically, Org export blocks and @@html:...@@ snippets allow HTML to pass through unescaped, leading to cross-site scripting (XSS) in the generated site. An attacker capable of supplying or influencing a content file under /content or the output of a content adapter can inject scripts that execute in the browsers of visitors. This issue only affects pages where the source file or content-adapter output declares the text/org media type.
Recommendations Update to version 0.166.0 or later. For sites that intentionally author Org Mode content, enable the feature by setting [security] allowContent = ['.*'] in the configuration.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100694
GHSA-PQ74-MJ4H-CJQ2

Affected Products

Hugo