---
id: CVE-2026-58402
aliases:
  - GHSA-q76j-gcg9-vxc6
title: 'Hugo: XSS via unescaped code-fence language in default code block renderer'
summary: 'Hugo: XSS via unescaped code-fence language in default code block renderer'
severity: medium
vendor: gohugoio
product: github.com/gohugoio/hugo
ecosystem: go
affected:
  - 'github.com/gohugoio/hugo >= 0.60.0, < 0.163.3'
patched:
  - github.com/gohugoio/hugo 0.163.3
published: '2026-06-19'
updated: '2026-07-08'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-q76j-gcg9-vxc6'
references:
  - url: 'https://github.com/gohugoio/hugo/security/advisories/GHSA-q76j-gcg9-vxc6'
  - url: 'https://github.com/gohugoio/hugo'
tags:
  - osv
  - go
epss: 0.003
epssPercentile: 0.20195
ingestedAt: '2026-07-09T18:56:36.690Z'
---

## Overview

Hugo's default code-block renderer wrote the Markdown code-fence language / info-string into the `<code class="language-…" data-lang="…">` wrapper without HTML escaping. A fence info-string containing a quote and a `<script>` payload breaks out of the attribute and injects a live script element.

This is not an issue if you fully trust every file under /content and every content adapter you load.

## Affected packages

- `github.com/gohugoio/hugo >= 0.60.0, < 0.163.3`

## Remediation

Upgrade to a patched release:

- `github.com/gohugoio/hugo 0.163.3`
