Junglewise Threat Intelligence

CVE-2026-50133: Hugo stored XSS via verbatim HTML content processing

CVE-2026-50133 · Severity: medium · CVSS 4 · Published 2026-07-06

Technologies: github.com/gohugoio/hugo (Go), Gohugoio Hugo, Hugo. Vendors: Go, Gohugoio, Hugo.

Executive brief

Hugo, a popular tool for building websites, was found to have a security flaw that could allow malicious code to be embedded in a site. If a website pulls content from untrusted sources like external APIs or third-party editors, an attacker could inject scripts that run in the browsers of site visitors. This could lead to unauthorized actions or the theft of user information. The issue has been addressed by disabling the automatic processing of raw HTML files by default.

Technical details

Hugo prior to version 0.162.0 is vulnerable to stored Cross-Site Scripting (XSS). The vulnerability exists because files mapped to the 'text/html' media type (such as .html files in the /content directory or those generated via content adapters) are emitted verbatim into the rendered static pages without sanitization. If a site's build pipeline ingests HTML from untrusted sources—such as a CMS, external API, or automated import—an attacker can inject malicious scripts. This has been mitigated in version 0.162.0 by introducing a 'security.allowContent' whitelist that denies 'text/html' by default. Users requiring this functionality must now explicitly opt-in via configuration.

Affected products

  • gohugoio Hugo < 0.162.0

Timeline

  • 2026-05-26: patched: Fix included in release v0.162.0
  • 2026-05-28: advisory: GitHub Security Advisory GHSA-c54g-xjwj-8g82 published
  • 2026-07-06: disclosed: CVE-2026-50133 published to NVD

References

Related threats