VendorsGohugohugoall versions
Vulnerabilities

Gohugo Hugo

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2020-26284
Hugo can execute a binary from the current directory on Windows
Published 2020-12-21 · Modified
8.5EPSS 0.015
CVE-2026-44301
Hugo: Node tool execution allows file system access outside the project directory
Published 2026-05-12 · Analyzed
8.1EPSS 0.004
CVE-2026-50135
Hugo: Symlink confinement bypass in resources.Get
Published 2026-07-06 · Analyzed
6.9EPSS 0.004
CVE-2026-58404
Hugo security.http.urls deny rules bypassed by alternate IPv4 encodings
Published 2026-07-06 · Analyzed
6.8EPSS 0.004
CVE-2026-58403
Hugo symlink confinement bypass in os.ReadFile
Published 2026-07-06 · Analyzed
6.5EPSS 0.005
CVE-2026-50134
Hugo: security.http.urls allow-list bypass via HTTP redirects
Published 2026-07-06 · Analyzed
6.3EPSS 0.004
CVE-2026-50133
Hugo: XSS via text/html content files
Published 2026-07-06 · Analyzed
6.1EPSS 0.003
CVE-2026-58402
Hugo default code block renderer XSS via unescaped code-fence language
Published 2026-07-06 · Analyzed
5.4EPSS 0.003
CVE-2026-35166
Hugo does not properly escape some Markdown links
Published 2026-04-06 · Analyzed
5.4EPSS 0.002