Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50133

Опубликовано: 06 июл. 2026
Источник: redhat
CVSS3: 6.1

Описание

Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (typically .html files under /content, or pages produced by a content adapter that sets content.mediaType = "text/html") had their body emitted verbatim into the rendered page. A site that ingests HTML content from an untrusted source could therefore be served stored cross-site scripting. This vulnerability is fixed in 0.162.0.

A flaw was found in Hugo, a static site generator. This vulnerability allows a remote attacker to perform stored cross-site scripting (XSS) by ingesting untrusted HTML content files. When a site processes these malicious files, the embedded script is executed verbatim in the rendered page, potentially leading to unauthorized actions or information disclosure in a user's browser.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2497463github.com/gohugoio/hugo: Hugo: Cross-site Scripting via untrusted HTML content files

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 1 месяца назад

Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (typically .html files under /content, or pages produced by a content adapter that sets content.mediaType = "text/html") had their body emitted verbatim into the rendered page. A site that ingests HTML content from an untrusted source could therefore be served stored cross-site scripting. This vulnerability is fixed in 0.162.0.

CVSS3: 6.1
nvd
около 1 месяца назад

Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (typically .html files under /content, or pages produced by a content adapter that sets content.mediaType = "text/html") had their body emitted verbatim into the rendered page. A site that ingests HTML content from an untrusted source could therefore be served stored cross-site scripting. This vulnerability is fixed in 0.162.0.

CVSS3: 6.1
debian
около 1 месяца назад

Hugo is a static site generator. Prior to 0.162.0, Hugo accepts conten ...

github
около 2 месяцев назад

Hugo: XSS via text/html content files

6.1 Medium

CVSS3