Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected. This vulnerability is fixed in 0.159.2.
References
| Link | Resource |
|---|---|
| https://github.com/gohugoio/hugo/security/advisories/GHSA-mcv8-8m8x-48pg | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
20 Apr 2026, 18:34
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| References | () https://github.com/gohugoio/hugo/security/advisories/GHSA-mcv8-8m8x-48pg - Vendor Advisory | |
| CPE | cpe:2.3:a:gohugo:hugo:*:*:*:*:*:linux:*:* cpe:2.3:a:gohugo:hugo:*:*:*:*:*:macos:*:* cpe:2.3:a:gohugo:hugo:*:*:*:*:*:windows:*:* |
|
| First Time |
Gohugo
Gohugo hugo |
06 Apr 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-06 18:16
Updated : 2026-06-17 10:40
NVD link : CVE-2026-35166
Mitre link : CVE-2026-35166
CVE.ORG link : CVE-2026-35166
JSON object : View
Products Affected
gohugo
- hugo
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
