PT-2026-38298 · Hugo · Hugo

Bacu79

+2

·

Published

2026-05-06

·

Updated

2026-05-21

·

CVE-2026-44301

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hugo versions prior to 0.161.0
Description When building a site that utilizes Node-based asset pipelines such as PostCSS, Babel, or TailwindCSS, the software invokes configured Node tools without restrictions on file system access. This allows code executed through these tools to read or write files outside the project's working directory when processing an untrusted site.
Recommendations Update to version 0.161.0 or later. As a temporary workaround, block the affected tools in the security.exec.allow configuration.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-44301
GHSA-X597-9FR4-5857

Affected Products

Hugo