Ad

CVE-2026-100694

MEDIUM CVSS 4.0: 5,1 EPSS 0.19%
Обновлено 30 сентября 2026
Hugo
Параметр Значение
CVSS 5,1 (MEDIUM)
Уязвимые версии 0.56.0 — 0.166.0
Устранено в версии 0.166.0
Тип уязвимости CWE-79 (Межсайтовый скриптинг (XSS))
Поставщик Hugo
Публичный эксплойт Нет

Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through unescaped, resulting in cross-site scripting (XSS) in the generated site. An attacker who can supply or influence a content file under /content or the output of a content adapter can inject scripts that execute in the browsers of visitors to the affected pages.

Only pages whose source file or content-adapter output declares the text/org media type are affected, and sites that fully trust all content sources are not impacted. Version v0.166.0 fixes the issue by introducing a security.allowContent allowlist that denies text/org by default; sites that intentionally author Org Mode content can opt back in with [security] allowContent = ['.*'].

Характеристики атаки

Способ атаки
По сети
Атака возможна удалённо
Сложность
Низкая
Легко эксплуатировать
Условия для атаки
Не требуются
Нет дополнительных условий
Нужны права
Не требуются
Права не нужны
Участие пользователя
Активное
Нужно действие пользователя

Последствия

Конфиденциальность
Нет
Нет утечки данных
Целостность
Нет
Нет модификации данных
Доступность
Нет
Нет нарушения работы

Строка CVSS v4.0

Уязвимые продукты 1

Конфигурация От (включительно) До (исключительно)
Gohugo Hugo
cpe:2.3:a:gohugo:hugo:*:*:*:*:*:*:*:*
0.56.0 0.166.0