go

github.com/gohugoio/hugo

View on go registry
17 Total advisories
17 Vulnerabilities
0 Malware

Vulnerabilities

UNKNOWN
Go

CVE-2026-58403

Hugo: Symlink confinement bypass in os.ReadFile

UNKNOWN
Go

CVE-2026-58404

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

UNKNOWN
Go

CVE-2026-58402

Hugo: XSS via unescaped code-fence language in default code block renderer

HIGH 7.7
Go

CVE-2020-26284

Hugo can execute a binary from the current directory on Windows

UNKNOWN
Go

CVE-2026-35166

Hugo: Certain markdown links are not properly escaped

UNKNOWN
Go

CVE-2026-50134

Hugo: security.http.urls allow-list bypass via HTTP redirects

UNKNOWN
Go

CVE-2026-50133

Hugo: XSS via text/html content files

UNKNOWN
Go

CVE-2026-50135

Hugo: Symlink confinement bypass in resources.Get

UNKNOWN
Go

CVE-2026-50134

Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo

UNKNOWN
Go

CVE-2026-50133

Hugo: XSS via text/html content files in github.com/gohugoio/hugo

UNKNOWN
Go

CVE-2026-35166

Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo

UNKNOWN
Go

CVE-2026-50135

Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo

UNKNOWN
Go

CVE-2026-44301

Hugo's Node tool execution allows file system access outside the project directory

UNKNOWN
Go

CVE-2024-55601

Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo

MEDIUM 6.1
Go

CVE-2024-32875

Hugo Markdown titles do not escaped in internal render hooks

UNKNOWN
Go

CVE-2024-32875

Hugo Markdown titles are not escaped in internal render hooks in github.com/gohugoio/hugo

UNKNOWN
Go

CVE-2024-55601

Hugo does not escape some attributes in internal templates

Ready to move

Start Securing

Free, no credit card | First findings in minutes