CVE-2026-100691

MEDIUM CVSS 4.0: 5.1 EPSS 0.17%
Updated Sep 29, 2026
Hugo
Parameter Value
CVSS 5.1 (MEDIUM)
Affected Versions 0.75.0 — 0.166.0
Fixed In 0.166.0
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Hugo
Public PoC No

Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `href` attributes of the generated line-number markup. A crafted `lineAnchors` value supplied as a Markdown code fence attribute (or passed to the `highlight` template function) results in unescaped HTML in the rendered page, allowing arbitrary JavaScript to execute in the browsers of visitors to the generated site. This affects sites that build and publish Markdown from untrusted contributors; Hugo's security model otherwise considers content trusted input.

Fixed in 0.166.0, where the `lineAnchors` value is HTML-escaped before being passed to Chroma.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Gohugo Hugo
cpe:2.3:a:gohugo:hugo:*:*:*:*:*:*:*:*
0.75.0 0.166.0