← Back to the live CVE advisory feed

CVE-2026-100690: hugo

Severity
8.7 (HIGH)
Vendor
GOHUGOIO
Affected versions
0.161.0 through before 0.166.0
Fixed version
0.166.0
Patch status
Patched
Published
2026-09-26T14:16:53.560
Modified
2026-09-26T14:16:53.560

Why it matters

This matters because the affected product may be exposed on public websites. A vulnerable plugin can create a direct path to site compromise, malicious code deployment, or data theft.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Check whether the affected WordPress plugin or theme is installed.
  • Update, disable, or remove the affected component if present.
  • Compare installed versions against the affected version range in the advisory.

Technical summary

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox. An attacker who can contribute content to a Hugo project (for example via a pull request) can commit a symlink such as assets/css/x.css -> /etc/passwd together with a PostCSS plugin that reads it, allowing any file readable by the Hugo build process to be disclosed and potentially embedded in the published site. This affects builds using the default security configuration; projects that do not invoke Node.js tools are unaffected. Fixed in v0.166.0, which scans allowed paths and fails the build when a symbolic link resolves outside them.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 26, 2026 04:00 PM UTC
416 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-100382
Mediawiki – ExternalData Extension PATCH
Reporter: C4F26CC8-17FF-4C99-B5E2-38FC1793EACC
10
CRITICAL
VIEW RECORD
CVE-2026-97163
UP plugin for Joomla
Reporter: SECURITY
10
CRITICAL
VIEW RECORD
CVE-2026-92161
oauth PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-18143
Request a Quote for WooCommerce
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-94132
AcyMailing Enterprise extension for Joomla PATCH
Reporter: SECURITY
9.5
CRITICAL
VIEW RECORD
CVE-2026-48482
glpi PATCH
Reporter: SECURITY-ADVISORIES
9.4
CRITICAL
VIEW RECORD
CVE-2026-100706
kyverno PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-100714
froxlor PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-100716
froxlor PATCH
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-97160
UP plugin for Joomla
Reporter: SECURITY
9.4
CRITICAL
VIEW RECORD
CVE-2026-97063
X-SpringBoot
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-97064
X-SpringBoot
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-100720
froxlor PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-94130
YouTube Gallery extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-100389
GestSup PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-100606
Flowise
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-100607
Flowise
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-100684
Product identification pending PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-97161
UP plugin for Joomla
Reporter: SECURITY
9.2
CRITICAL
VIEW RECORD
CVE-2026-39353
InvoicePlane PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-42322
Piwigo PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-62262
Piwigo
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-84458
zammad PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-100390
Product identification pending
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-100551
OpenClaw PATCH
Reporter: DISCLOSURE
9
CRITICAL
VIEW RECORD
CVE-2026-100567
Product identification pending PATCH
Reporter: DISCLOSURE
8.9
HIGH
VIEW RECORD
CVE-2026-100683
Product identification pending PATCH
Reporter: DISCLOSURE
8.9
HIGH
VIEW RECORD
CVE-2026-94445
Product identification pending
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-61525
zammad PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-100391
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-96795
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-100597
Product identification pending PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-100676
stoatchat PATCH
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-89032
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-56725
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-56733
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-100520
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100544
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100552
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100557
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100558
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100568
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100575
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100580
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100586
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100587
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100588
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100589
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100596
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100599
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100603
clawhub PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100608
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100614
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100615
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100617
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100618
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100619
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100622
Product identification pending
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100623
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100625
capgo.app
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100628
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100631
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100644
siyuan PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100656
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100657
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100660
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100661
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100662
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100663
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100664
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100665
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100669
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100670
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100672
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100682
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100689
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100690
hugo PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100692
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100700
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-100711
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-84462
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-97060
X-SpringBoot
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100372
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100559
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100561
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100585
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100612
capgo.app
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100639
siyuan PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100640
siyuan PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100641
siyuan PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100645
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100646
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100671
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100680
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100686
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-100693
hugo PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-47679
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-55214
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-71483
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.5
HIGH
VIEW RECORD
CVE-2026-100530
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.