PT-2026-38298 · Hugo · Hugo
Bacu79
+2
·
Published
2026-05-06
·
Updated
2026-05-21
·
CVE-2026-44301
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Hugo versions prior to 0.161.0
Description
When building a site that utilizes Node-based asset pipelines such as PostCSS, Babel, or TailwindCSS, the software invokes configured Node tools without restrictions on file system access. This allows code executed through these tools to read or write files outside the project's working directory when processing an untrusted site.
Recommendations
Update to version 0.161.0 or later.
As a temporary workaround, block the affected tools in the
security.exec.allow configuration.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hugo