CVE-2026-35166Medium▾ SunlitHugo: Certain markdown links are not properly escaped
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
Links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected.
Patched in v0.159.2
Create custom render hooks for links and images in a Hugo theme/project.
github.com/gohugoio/hugo >= 0.60.0, < 0.159.2Upgrade to a patched release:
github.com/gohugoio/hugo 0.159.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44301MediumHugo's Node tool execution allows file system access outside the project directory
CVE-2026-58404HighHugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
CVE-2026-58402MediumHugo: XSS via unescaped code-fence language in default code block renderer
CVE-2026-58403MediumHugo: Symlink confinement bypass in os.ReadFile
CVE-2020-26284High· 7.7Hugo can execute a binary from the current directory on Windows
CVE-2026-50133MediumHugo: XSS via text/html content files