Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mcv8-8m8x-48pg

Опубликовано: 03 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 5.3

Описание

Hugo: Certain markdown links are not properly escaped

Impact

Links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected.

Patches

Patched in v0.159.2

Workarounds

Create custom render hooks for links and images in a Hugo theme/project.

Пакеты

Наименование

github.com/gohugoio/hugo

go
Затронутые версииВерсия исправления

>= 0.60.0, < 0.159.2

0.159.2

EPSS

Процентиль: 8%
0.00185
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
4 месяца назад

Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected. This vulnerability is fixed in 0.159.2.

CVSS3: 4.6
redhat
4 месяца назад

Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected. This vulnerability is fixed in 0.159.2.

CVSS3: 5.4
nvd
4 месяца назад

Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected. This vulnerability is fixed in 0.159.2.

CVSS3: 5.4
debian
4 месяца назад

Hugo is a static site generator. From 0.60.0 to before 0.159.2, links ...

EPSS

Процентиль: 8%
0.00185
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-79