Junglewise Threat Intelligence

CVE-2026-58403: Hugo symlink confinement bypass in virtual filesystem

CVE-2026-58403 · Severity: medium · CVSS 4 · Published 2026-07-06

Technologies: github.com/gohugoio/hugo (Go), Gohugoio Hugo, Hugo. Vendors: Go, Gohugoio, Hugo.

Executive brief

Hugo, a popular tool for building websites, contains a security flaw that could allow unauthorized access to files on a developer's computer. If a user is tricked into using a malicious website theme or plugin containing a specially crafted shortcut (symlink), the tool may inadvertently read and expose sensitive files located outside of the project folder. This could lead to the theft of private data or credentials accessible to the user running the software.

Technical details

A regression in Hugo's virtual filesystem (specifically within RootMappingFs.statRoot) caused the application to use Stat instead of Lstat. Because Stat follows symbolic links, an attacker who can place a malicious symlink within a mounted directory (such as a local theme) can bypass the intended filesystem confinement. When Hugo performs a direct file read on such a symlink, it returns the contents of the target file outside the mount tree. This vulnerability affects versions v0.123.0 through v0.163.0 and is fixed in v0.163.1. Exploitation requires the victim to process a malicious local mount or theme; themes downloaded as Go modules are not affected as symlinks are stripped during download.

Affected products

  • gohugoio Hugo >= 0.123.0, < 0.163.1

Timeline

  • 2026-06-10: patched: Fix merged into master branch
  • 2026-06-11: advisory: Release v0.163.1 published
  • 2026-07-06: disclosed: CVE published to NVD

References

Related threats