gohugoio has 14 CVEs on record between 2021 and 2026. Disclosures have slowed: 2 in the last 90 days after 11 in the 90 before. The busiest recent month was June 2026 with 9. The median CVSS is 7.7 (high), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-59 (3). Most affected products: github.com/gohugoio/hugo (12), hugo (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —
- Last 90 days
- 2 prev 11
Worst active — by depth score
CVE-2026-89259Critical· 9.8Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS54CVE-2020-26284High· 7.7Hugo can execute a binary from the current directory on Windows43GHSA-r46f-3rpw-hxrvHighHugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)41CVE-2026-58404HighHugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)41CVE-2026-89258Medium· 6.3Hugo is a static site generator35
gohugoio vulnerabilities
CVEs affecting gohugoio, newest first. Open any entry for full detail, references, and exploit status.
14 CVEsRSS
CVE-2026-89259Critical· 9.8Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS
Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --al…
CVE-2026-89258Medium· 6.3Hugo is a static site generator
Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place — or who…
CVE-2026-58404HighHugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
CVE-2026-58402MediumHugo: XSS via unescaped code-fence language in default code block renderer
Hugo: XSS via unescaped code-fence language in default code block renderer
CVE-2026-58403MediumHugo: Symlink confinement bypass in os.ReadFile
Hugo: Symlink confinement bypass in os.ReadFile
GHSA-q76j-gcg9-vxc6MediumHugo: XSS via unescaped code-fence language in default code block renderer
Hugo: XSS via unescaped code-fence language in default code block renderer
GHSA-c3wq-j5vh-68rcMediumHugo: Symlink confinement bypass in os.ReadFile
Hugo: Symlink confinement bypass in os.ReadFile
GHSA-r46f-3rpw-hxrvHighHugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)
CVE-2026-50133MediumHugo: XSS via text/html content files
Hugo: XSS via text/html content files
CVE-2026-50134MediumHugo: security.http.urls allow-list bypass via HTTP redirects
Hugo: security.http.urls allow-list bypass via HTTP redirects
CVE-2026-50135MediumHugo: Symlink confinement bypass in resources.Get
Hugo: Symlink confinement bypass in resources.Get
CVE-2026-44301MediumHugo's Node tool execution allows file system access outside the project directory
Hugo's Node tool execution allows file system access outside the project directory
CVE-2026-35166MediumHugo: Certain markdown links are not properly escaped
Hugo: Certain markdown links are not properly escaped
CVE-2020-26284High· 7.7Hugo can execute a binary from the current directory on Windows
Hugo can execute a binary from the current directory on Windows