Executive brief
Hugo is a popular tool used to build websites from content files. A security flaw was found where a malicious website theme or configuration could use special file shortcuts (symlinks) to trick the tool into reading private files from the computer running the software. This could allow an attacker to steal sensitive information that the user has access to on their local system.
Technical details
A symlink confinement bypass exists in Hugo's virtual filesystem due to a regression in version 0.123.0. The root cause is located in `RootMappingFs.statRoot`, which incorrectly calls `Stat` (following symlinks) instead of `Lstat`. An attacker who can place a malicious symlink within a mounted directory, such as a locally-vendored theme, can use `os.ReadFile` or `resources.Get` to read arbitrary files outside the mount boundary. This vulnerability is limited to files reachable by the user account running the Hugo process. The issue was fixed in version 0.163.1 by ensuring symlinks are not followed during these operations.
Affected products
- gohugoio Hugo >= 0.123.0, < 0.163.1
Timeline
- 2026-06-18: disclosed
- 2026-06-19: advisory
- 2026-06-19: patched: Fixed in v0.163.1