Executive brief
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo
Affected products
- Go github.com/gohugoio/hugo
Junglewise Threat Intelligence
CVE-2026-35166 · Severity: medium · CVSS 4 · Published 2026-07-07
Technologies: github.com/gohugoio/hugo (Go). Vendors: Go.
Hugo: Certain markdown links are not properly escaped in github.com/gohugoio/hugo