Junglewise Threat Intelligence

CVE-2026-89259: Hugo insufficient permission restriction via TailwindCSS

CVE-2026-89259 · Severity: critical · CVSS 9.8 · Published 2026-09-11

Technologies: Hugo. Vendors: Hugo.

Executive brief

Hugo is a static site generator that allows websites to be built by processing content files. Starting in version 0.161.0, Hugo began running Node-based tools like TailwindCSS with restricted permissions, but TailwindCSS requires extremely permissive access that bypasses these security restrictions. An attacker can exploit this to read and write files anywhere on a system when building an untrusted website, potentially exposing sensitive data or modifying system files.

Technical details

This vulnerability is a privilege escalation in Hugo's Node tool execution sandbox. From v0.161.0, Hugo implemented a permission model for Node tools (intended to fix GHSA-x597-9fr4-5857), but TailwindCSS—included by default in the security.exec.allow list—requires highly permissive flags (--allow-addons, --allow-child-process, --allow-worker) that defeat the sandbox restrictions. An unauthenticated attacker can craft a malicious website project and distribute it to users; when a user builds the project locally with Hugo, the Node tool can read/write files outside the project working directory. The vulnerability affects Hugo versions 0.43 through 0.164.x. It was fixed in v0.165.0 by removing TailwindCSS from the default allowed list. Users can mitigate by explicitly defining a restrictive security.exec.allow configuration in hugo.toml.

Affected products

  • Hugo Hugo >0.43, <0.165.0

Timeline

  • 2026-08-27: disclosed: GitHub Security Advisory GHSA-vrm6-x8vp-mv2r published
  • 2026-09-11: advisory: CVE-2026-89259 assigned and published to NVD
  • 2026: patched: Fixed in Hugo v0.165.0 by removing TailwindCSS from default security.exec.allow list

References

Related threats