{"schema_version":1,"title":"Gohugoio Hugo vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in Gohugoio Hugo: 4 in the last 7 days and 10 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100694, was published on 26 September 2026.","url":"https://junglewise.ai/threats/technologies/gohugoio-hugo","json_url":"https://junglewise.ai/threats/technologies/gohugoio-hugo.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/gohugoio-hugo","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":11,"critical":0,"exploited":0,"last_7_days":4,"last_30_days":4,"last_90_days":10,"last_365_days":11},"latest":[{"cve":"CVE-2026-100694","cvss":6.1,"slug":"cve-2026-100694-hugo-is-a-static-site-generator-in-versions-from-v0-56-0-through","title":"Hugo cross-site scripting via text/org content files","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:54.15+00:00","url":"https://junglewise.ai/threats/cve-2026-100694-hugo-is-a-static-site-generator-in-versions-from-v0-56-0-through"},{"cve":"CVE-2026-100693","cvss":8.4,"slug":"cve-2026-100693-hugo-versions-from-v0-162-0-before-v0-166-0-contain-a-case","title":"Hugo case-sensitive URL scheme validation bypass in security.http.urls","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:54.007+00:00","url":"https://junglewise.ai/threats/cve-2026-100693-hugo-versions-from-v0-162-0-before-v0-166-0-contain-a-case"},{"cve":"CVE-2026-100692","cvss":7.5,"slug":"cve-2026-100692-hugo-is-a-static-site-generator-in-versions-after-v0-123-0-and","title":"Hugo symlink confinement bypass in mount roots","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:53.86+00:00","url":"https://junglewise.ai/threats/cve-2026-100692-hugo-is-a-static-site-generator-in-versions-after-v0-123-0-and"},{"cve":"CVE-2026-100690","cvss":7.5,"slug":"cve-2026-100690-hugo-versions-from-v0-161-0-through-v0-165-0-run-node-js-tools","title":"Hugo arbitrary file read via symlinks in Node.js tools","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:53.56+00:00","url":"https://junglewise.ai/threats/cve-2026-100690-hugo-versions-from-v0-161-0-through-v0-165-0-run-node-js-tools"},{"cve":"CVE-2026-50135","cvss":4,"epss":0.0041,"slug":"cve-2026-50135-hugo-symlink-confinement-bypass-in-resources-get","title":"Hugo symlink confinement bypass in resources.Get","severity":"medium","exploited":false,"published_at":"2026-07-06T21:16:56.347+00:00","url":"https://junglewise.ai/threats/cve-2026-50135-hugo-symlink-confinement-bypass-in-resources-get"},{"cve":"CVE-2026-58404","cvss":4,"epss":0.0037,"slug":"cve-2026-58404-hugo-ssrf-bypass-via-alternate-ipv4-encodings-in-security-http","title":"Hugo SSRF bypass via alternate IPv4 encodings in security.http.urls","severity":"medium","exploited":false,"published_at":"2026-07-06T20:16:38.307+00:00","url":"https://junglewise.ai/threats/cve-2026-58404-hugo-ssrf-bypass-via-alternate-ipv4-encodings-in-security-http"},{"cve":"CVE-2026-58403","cvss":4,"epss":0.0048,"slug":"cve-2026-58403-hugo-symlink-confinement-bypass-in-virtual-filesystem","title":"Hugo symlink confinement bypass in virtual filesystem","severity":"medium","exploited":false,"published_at":"2026-07-06T20:16:38.173+00:00","url":"https://junglewise.ai/threats/cve-2026-58403-hugo-symlink-confinement-bypass-in-virtual-filesystem"},{"cve":"CVE-2026-58402","cvss":4,"epss":0.003,"slug":"cve-2026-58402-hugo-xss-in-default-code-block-renderer","title":"Hugo XSS in default code-block renderer","severity":"medium","exploited":false,"published_at":"2026-07-06T20:16:38.04+00:00","url":"https://junglewise.ai/threats/cve-2026-58402-hugo-xss-in-default-code-block-renderer"},{"cve":"CVE-2026-50134","cvss":0,"epss":0.004,"slug":"cve-2026-50134-hugo-ssrf-via-http-redirect-bypass-in-resources-getremote","title":"Hugo SSRF via HTTP redirect bypass in resources.GetRemote","severity":"medium","exploited":false,"published_at":"2026-07-06T20:16:37.197+00:00","url":"https://junglewise.ai/threats/cve-2026-50134-hugo-ssrf-via-http-redirect-bypass-in-resources-getremote"},{"cve":"CVE-2026-50133","cvss":4,"epss":0.0033,"slug":"cve-2026-50133-hugo-stored-xss-via-verbatim-html-content-processing","title":"Hugo stored XSS via verbatim HTML content processing","severity":"medium","exploited":false,"published_at":"2026-07-06T20:16:37.043+00:00","url":"https://junglewise.ai/threats/cve-2026-50133-hugo-stored-xss-via-verbatim-html-content-processing"},{"cve":"CVE-2026-44301","cvss":8.1,"epss":0.0043,"slug":"cve-2026-44301-hugo-path-traversal-in-node-based-asset-pipelines","title":"Hugo path traversal in Node-based asset pipelines","severity":"high","exploited":false,"published_at":"2026-05-12T22:16:36.843+00:00","url":"https://junglewise.ai/threats/cve-2026-44301-hugo-path-traversal-in-node-based-asset-pipelines"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Gohugoio Hugo","slug":"gohugoio-hugo","vendor":{"name":"Gohugoio","slug":"gohugoio","url":"https://junglewise.ai/threats/vendors/gohugoio"},"aliases":[],"category":"static site generator","url":"https://junglewise.ai/threats/technologies/gohugoio-hugo"},"most_severe":[{"cve":"CVE-2026-100693","cvss":8.4,"slug":"cve-2026-100693-hugo-versions-from-v0-162-0-before-v0-166-0-contain-a-case","title":"Hugo case-sensitive URL scheme validation bypass in security.http.urls","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:54.007+00:00","url":"https://junglewise.ai/threats/cve-2026-100693-hugo-versions-from-v0-162-0-before-v0-166-0-contain-a-case"},{"cve":"CVE-2026-44301","cvss":8.1,"epss":0.0043,"slug":"cve-2026-44301-hugo-path-traversal-in-node-based-asset-pipelines","title":"Hugo path traversal in Node-based asset pipelines","severity":"high","exploited":false,"published_at":"2026-05-12T22:16:36.843+00:00","url":"https://junglewise.ai/threats/cve-2026-44301-hugo-path-traversal-in-node-based-asset-pipelines"},{"cve":"CVE-2026-100692","cvss":7.5,"slug":"cve-2026-100692-hugo-is-a-static-site-generator-in-versions-after-v0-123-0-and","title":"Hugo symlink confinement bypass in mount roots","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:53.86+00:00","url":"https://junglewise.ai/threats/cve-2026-100692-hugo-is-a-static-site-generator-in-versions-after-v0-123-0-and"},{"cve":"CVE-2026-100690","cvss":7.5,"slug":"cve-2026-100690-hugo-versions-from-v0-161-0-through-v0-165-0-run-node-js-tools","title":"Hugo arbitrary file read via symlinks in Node.js tools","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:53.56+00:00","url":"https://junglewise.ai/threats/cve-2026-100690-hugo-versions-from-v0-161-0-through-v0-165-0-run-node-js-tools"},{"cve":"CVE-2026-100694","cvss":6.1,"slug":"cve-2026-100694-hugo-is-a-static-site-generator-in-versions-from-v0-56-0-through","title":"Hugo cross-site scripting via text/org content files","severity":"medium","exploited":false,"published_at":"2026-09-26T14:16:54.15+00:00","url":"https://junglewise.ai/threats/cve-2026-100694-hugo-is-a-static-site-generator-in-versions-from-v0-56-0-through"},{"cve":"CVE-2026-58403","cvss":4,"epss":0.0048,"slug":"cve-2026-58403-hugo-symlink-confinement-bypass-in-virtual-filesystem","title":"Hugo symlink confinement bypass in virtual filesystem","severity":"medium","exploited":false,"published_at":"2026-07-06T20:16:38.173+00:00","url":"https://junglewise.ai/threats/cve-2026-58403-hugo-symlink-confinement-bypass-in-virtual-filesystem"},{"cve":"CVE-2026-50135","cvss":4,"epss":0.0041,"slug":"cve-2026-50135-hugo-symlink-confinement-bypass-in-resources-get","title":"Hugo symlink confinement bypass in resources.Get","severity":"medium","exploited":false,"published_at":"2026-07-06T21:16:56.347+00:00","url":"https://junglewise.ai/threats/cve-2026-50135-hugo-symlink-confinement-bypass-in-resources-get"},{"cve":"CVE-2026-58404","cvss":4,"epss":0.0037,"slug":"cve-2026-58404-hugo-ssrf-bypass-via-alternate-ipv4-encodings-in-security-http","title":"Hugo SSRF bypass via alternate IPv4 encodings in security.http.urls","severity":"medium","exploited":false,"published_at":"2026-07-06T20:16:38.307+00:00","url":"https://junglewise.ai/threats/cve-2026-58404-hugo-ssrf-bypass-via-alternate-ipv4-encodings-in-security-http"},{"cve":"CVE-2026-50133","cvss":4,"epss":0.0033,"slug":"cve-2026-50133-hugo-stored-xss-via-verbatim-html-content-processing","title":"Hugo stored XSS via verbatim HTML content processing","severity":"medium","exploited":false,"published_at":"2026-07-06T20:16:37.043+00:00","url":"https://junglewise.ai/threats/cve-2026-50133-hugo-stored-xss-via-verbatim-html-content-processing"},{"cve":"CVE-2026-58402","cvss":4,"epss":0.003,"slug":"cve-2026-58402-hugo-xss-in-default-code-block-renderer","title":"Hugo XSS in default code-block renderer","severity":"medium","exploited":false,"published_at":"2026-07-06T20:16:38.04+00:00","url":"https://junglewise.ai/threats/cve-2026-58402-hugo-xss-in-default-code-block-renderer"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}