hugo vulnerabilities
CVEs whose affected-version data names the hugo package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-89259Critical· 9.8Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS
Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --al…
▾ Midnightgohugoio · hugoEPSS 0.41%via CVEORG
CVE-2026-89258Medium· 6.3Hugo is a static site generator
Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place — or who…
▾ Sunlitgohugoio · hugoEPSS 0.32%via NVD