VulnSea

gohugo has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 5. The median CVSS is 7.5 (high). None have a confirmed exploitation report. The most common weakness class is CWE-79 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
—
Last 90 days
7 prev 0

Products

  • hugo 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

gohugo vulnerabilities

CVEs affecting gohugo, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-100690High· 7.5⚖ disputed
3d ago

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js …

▾ Twilightgohugo · hugoEPSS 0.35%via NVD
CVE-2026-100692High· 7.5⚖ disputed
3d ago

Hugo is a static site generator

Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink…

▾ Twilightgohugo · hugoEPSS 0.44%via NVD
CVE-2026-100691Medium· 5.4
3d ago

Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `hre…

Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `hre…

▾ Sunlitgohugo · hugoEPSS 0.17%via NVD
CVE-2026-100693High· 8.4⚖ disputed
3d ago

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions

Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRe…

▾ Twilightgohugo · hugoEPSS 0.13%via NVD
CVE-2026-100694Medium· 6.1
3d ago

Hugo is a static site generator

Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through unescaped, …

▾ Sunlitgohugo · hugoEPSS 0.19%via NVD
CVE-2026-10618Medium· 5.4
1mo ago

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every attribute value from a b…

▾ Sunlitgohugo · hugoEPSS 0.21%via NVD
CVE-2026-75926High· 8.6
1mo ago

Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory

Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could not reach the file system outside the project directory. Hugo 0.162.0 added tailwindcss to…

▾ Twilightgohugo · hugoEPSS 0.22%via NVD
gohugo vulnerabilities (CVEs) · VulnSea