
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-100692 is a symlink traversal (link following) vulnerability in Hugo, the open-source static site generator, classified as an information disclosure issue. In Hugo versions after v0.123.0 and before v0.166.0, symlink confinement checks stopped at the mount root itself, allowing a theme or vendored module to contain a symlink at a mount root (e.g., themes/mytheme/assets -> /some/dir/outside) that bypasses Hugo's security model. The vulnerability was disclosed on September 26, 2026, and is fixed in v0.166.0. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Hugo Advisory).
The root cause is CWE-59 (Improper Link Resolution Before File Access — 'Link Following'): Hugo's symlink confinement logic validated that mount sources were local paths but failed to check whether the mount root directory itself was a symlink pointing outside the project (GitHub Advisory). An attacker who can introduce a malicious theme or vendored module into a Hugo project can place a symlink at a mount root (e.g., themes/mytheme/assets -> /etc/) so that Hugo's resources.Get, resources.Match, and static mount functions traverse the symlink and read arbitrary files from the build system's filesystem. Modules fetched via Go modules are not affected because Go module zip archives cannot contain symlinks. The attack requires the ability to commit or supply a malicious theme/module to the target Hugo project, but no authentication or special privileges on the build system itself are needed (Hugo Advisory, Red Hat Bugzilla).
Successful exploitation allows an attacker to read arbitrary files from the build system's filesystem during site generation and potentially publish them to the public/ output directory, making sensitive files (e.g., credentials, private keys, configuration files) accessible via the generated static site. The impact is limited to confidentiality — there is no integrity or availability impact. The scope is confined to the vulnerable system, but the exposure of build-system files could enable further attacks such as credential theft or lateral movement if sensitive secrets are disclosed (GitHub Advisory, Hugo Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.44% (34th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. NVD's SSVC assessment notes the vulnerability is automatable with partial technical impact and no known exploitation (GitHub Advisory).
themes/mytheme/) and replace a mount root subdirectory (e.g., themes/mytheme/assets) with a symlink pointing to a sensitive directory outside the project root (e.g., ln -s /etc themes/mytheme/assets or ln -s /home/user/.ssh themes/mytheme/assets).hugo CLI invocation). Hugo's symlink confinement check passes because it only validates the mount root path, not whether the root itself is a symlink.resources.Get, resources.Match, or static mounts traversing the symlink. Files from the target directory are processed and may be published to public/, making them accessible via the generated site or build artifacts (Hugo Advisory, GitHub Advisory).themes/ or _vendor/ (e.g., themes/mytheme/assets -> /some/absolute/path); unexpected files in the public/ output directory that do not correspond to legitimate site content (e.g., /etc/passwd, SSH keys, .env files)./etc/, /home/, /root/, /var/) as observed via strace, auditd, or similar file access monitoring tools.themes/ or _vendor/ subdirectories, particularly at mount root level (Hugo Advisory).Upgrade Hugo to v0.166.0 or later, where symlinked mount roots and symlinked directories between the mount root and the module directory are treated as non-existent for all modules, including the main project (Hugo Advisory). As a workaround for environments that cannot immediately upgrade, manually inspect themes/ and vendored modules for symlinks at mount roots before each build (e.g., using find themes/ _vendor/ -maxdepth 2 -type l), and replace any symlinks with explicit mount configurations in hugo.toml. CI/CD pipelines should also enforce pre-build symlink checks as a defense-in-depth measure (GitHub Advisory, Red Hat Bugzilla).
The vulnerability was credited to researcher DONG2209 in the official Hugo security advisory (Hugo Advisory). Red Hat tracked the issue via Bugzilla and assigned it medium priority/severity, indicating awareness among enterprise Linux distributors (Red Hat Bugzilla). The advisory references related Hugo symlink advisories (GHSA-vrv5-r5rf-6v4j, GHSA-c3wq-j5vh-68rc, GHSA-fw87-fv5r-9fpw), suggesting a broader pattern of symlink confinement issues being addressed in the Hugo project. No significant social media controversy or major media coverage has been identified.
Disponibilidade de correção em distribuições Linux principais e suas versões.
bionic (esm-apps)
hugo
devel
hugo
focal (esm-apps)
hugo
jammy
hugo
jammy (esm-apps)
hugo
noble
hugo
noble (esm-apps)
hugo
resolute
hugo
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."