go

github.com/gohugoio/hugo

View on go registry
17 Total advisories
17 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/gohugoio/hugo is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

CVE-2026-58403

Hugo: Symlink confinement bypass in os.ReadFile

UNKNOWN
Go

CVE-2026-58404

Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF)

UNKNOWN
Go

CVE-2026-58402

Hugo: XSS via unescaped code-fence language in default code block renderer

HIGH 7.7
Go

CVE-2020-26284

Hugo can execute a binary from the current directory on Windows

UNKNOWN
Go

CVE-2026-35166

Hugo: Certain markdown links are not properly escaped

UNKNOWN
Go

CVE-2026-50134

Hugo: security.http.urls allow-list bypass via HTTP redirects

UNKNOWN
Go

CVE-2026-50133

Hugo: XSS via text/html content files

UNKNOWN
Go

CVE-2026-50135

Hugo: Symlink confinement bypass in resources.Get

UNKNOWN
Go

CVE-2026-50134

Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo

UNKNOWN
Go

CVE-2026-50133

Hugo: XSS via text/html content files in github.com/gohugoio/hugo

UNKNOWN
Go

CVE-2026-35166

Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo

UNKNOWN
Go

CVE-2026-50135

Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo

UNKNOWN
Go

CVE-2026-44301

Hugo's Node tool execution allows file system access outside the project directory

UNKNOWN
Go

CVE-2024-55601

Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo

MEDIUM 6.1
Go

CVE-2024-32875

Hugo Markdown titles do not escaped in internal render hooks

UNKNOWN
Go

CVE-2024-32875

Hugo Markdown titles are not escaped in internal render hooks in github.com/gohugoio/hugo

UNKNOWN
Go

CVE-2024-55601

Hugo does not escape some attributes in internal templates

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes