Ad

CVE-2026-100691

MEDIUM CVSS 4.0: 5,1 EPSS 0.17%
Обновлено 29 сентября 2026
Hugo
Параметр Значение
CVSS 5,1 (MEDIUM)
Уязвимые версии 0.75.0 — 0.166.0
Устранено в версии 0.166.0
Тип уязвимости CWE-79 (Межсайтовый скриптинг (XSS))
Поставщик Hugo
Публичный эксплойт Нет

Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `href` attributes of the generated line-number markup. A crafted `lineAnchors` value supplied as a Markdown code fence attribute (or passed to the `highlight` template function) results in unescaped HTML in the rendered page, allowing arbitrary JavaScript to execute in the browsers of visitors to the generated site. This affects sites that build and publish Markdown from untrusted contributors; Hugo's security model otherwise considers content trusted input.

Fixed in 0.166.0, where the `lineAnchors` value is HTML-escaped before being passed to Chroma.

Характеристики атаки

Способ атаки
По сети
Атака возможна удалённо
Сложность
Низкая
Легко эксплуатировать
Условия для атаки
Не требуются
Нет дополнительных условий
Нужны права
Низкие
Нужны базовые права
Участие пользователя
Пассивное
Минимальное взаимодействие

Последствия

Конфиденциальность
Нет
Нет утечки данных
Целостность
Нет
Нет модификации данных
Доступность
Нет
Нет нарушения работы

Строка CVSS v4.0

Уязвимые продукты 1

Конфигурация От (включительно) До (исключительно)
Gohugo Hugo
cpe:2.3:a:gohugo:hugo:*:*:*:*:*:*:*:*
0.75.0 0.166.0