Junglewise Threat Intelligence

CVE-2026-44301: Hugo path traversal in Node-based asset pipelines

CVE-2026-44301 · Severity: high · CVSS 8.1 · Published 2026-05-12

Technologies: github.com/gohugoio/hugo (Go), Gohugoio Hugo, Hugo. Vendors: Go, Gohugoio, Hugo.

Executive brief

Hugo is a popular tool used to build websites from source files. A security flaw was found where building a website from an untrusted source could allow malicious code to read or write files anywhere on the developer's computer. This could lead to the theft of sensitive data or the modification of system files if a user attempts to build a compromised project.

Technical details

Hugo versions 0.43 through 0.160.x contain a path traversal vulnerability (CWE-22) when processing Node-based asset pipelines such as PostCSS, Babel, or TailwindCSS. The root cause is that Hugo invoked these external Node.js tools without enforcing file system restrictions or utilizing Node's permission model. An attacker can exploit this by providing a malicious Hugo site configuration or source files that, when built, execute code via these tools to read or write files outside the project's working directory. This requires the victim to run the 'hugo' command on an untrusted project. The vulnerability is fixed in version 0.161.0, which implements Node's permission model to restrict access to the site source directories.

Affected products

  • gohugoio Hugo 0.43 to 0.161.0

Timeline

  • 2026-04-28: advisory: Vendor advisory published on GitHub
  • 2026-05-12: disclosed: CVE published to NVD

References

Related threats