Vulnerability DatabaseCVE-2026-100690

CVE-2026-100690: 
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-100690 is a symbolic link (symlink) sandbox escape vulnerability in the Hugo static site generator that allows arbitrary file read during the build process. It affects Hugo versions v0.161.0 through v0.165.0, which introduced a Node.js permission model sandbox for Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel). Because the Node.js permission model validates only the lexical path and follows symbolic links without verifying their resolved targets, an attacker with content contribution access can commit a symlink pointing outside the project directory to expose sensitive files. The vulnerability was disclosed on September 26, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, Hugo Security Advisory).

Technical details

The root cause is CWE-59 (Improper Link Resolution Before File Access — 'Link Following'): the Node.js permission model, as used by Hugo, checks only the lexical (string-based) representation of a path rather than resolving symbolic links before validating access, allowing symlinks to escape the sandboxed project directory (GitHub Advisory). An attacker with write access to a Hugo project repository (e.g., via a pull request) can commit a crafted symlink such as assets/css/x.css -> /etc/passwd alongside a PostCSS plugin configured to read that file; when Hugo invokes the Node.js tool during the build, the symlink is followed and the target file's contents are read and potentially embedded in the generated site (Hugo Security Advisory). The precondition is that the project must invoke at least one Node.js tool (PostCSS, TailwindCSS, or Babel) under the default security configuration; projects not using these tools are unaffected. Notably, versions prior to v0.161.0 had no sandbox at all, meaning Node.js plugins could read arbitrary files directly without needing a symlink (Hugo Security Advisory).

Impact

Successful exploitation results in a high-confidentiality-impact file disclosure: any file readable by the Hugo build process (e.g., /etc/passwd, SSH private keys, environment files containing secrets, cloud credentials) can be exfiltrated and potentially published as part of the generated static site, making sensitive data publicly accessible (Hugo Security Advisory, GitHub Advisory). There is no integrity or availability impact from this vulnerability itself, but disclosed secrets (API keys, credentials) could enable lateral movement or further compromise of downstream systems (Feedly). CI/CD build environments are particularly at risk, as they often have access to sensitive credentials and configuration files.

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure (Feedly). The EPSS score is 0.0, reflecting low current exploitation probability (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the ability to contribute content to a Hugo project (e.g., via a pull request or direct commit access), limiting the attacker pool to those with at least partial repository access.

Exploitation steps

  1. Gain repository access: Obtain the ability to contribute content to a target Hugo project using an affected version (v0.161.0–v0.165.0) — for example, by submitting a pull request to an open-source project or exploiting weak branch protection policies.
  2. Identify target file: Determine a sensitive file readable by the Hugo build process on the CI/CD server, such as /etc/passwd, ~/.ssh/id_rsa, .env, or cloud credential files.
  3. Create a malicious symlink: Commit a symbolic link within the project's asset directory pointing to the target file outside the project tree, e.g., assets/css/x.css -> /etc/passwd.
  4. Add or modify a PostCSS plugin: Include or modify a PostCSS configuration/plugin (e.g., postcss.config.js) that reads the symlinked file and outputs its contents — for example, by embedding the file content as a CSS comment or variable in the generated output.
  5. Trigger the build: Wait for or trigger a Hugo build (e.g., via CI/CD pipeline on pull request), which invokes the Node.js PostCSS tool. The Node.js permission model follows the symlink without detecting it escapes the sandbox.
  6. Harvest disclosed data: Retrieve the sensitive file contents from the published site output or build artifacts, where they have been embedded by the PostCSS plugin (Hugo Security Advisory, GitHub Advisory).

Indicators of compromise

  • File System: Presence of symbolic links in the Hugo project's asset directories (e.g., assets/css/, assets/js/) that resolve to paths outside the project root, particularly pointing to sensitive system files (/etc/passwd, ~/.ssh/, /proc/, .env files).
  • File System: Unexpected or modified postcss.config.js, tailwind.config.js, or Babel configuration files containing file-read logic or unusual plugin references.
  • Build Artifacts: Published site output containing content that appears to be system file data (e.g., /etc/passwd format strings, private key headers, environment variable patterns) embedded in CSS or JS files.
  • Logs: Hugo build logs showing Node.js tool invocations that access paths outside the configured project directory or mounts.
  • Version Control: Git history showing newly committed symlinks in asset directories, especially those added via pull requests from external contributors.

Mitigation and workarounds

Upgrade Hugo to v0.166.0 or later, which resolves the issue by scanning all allowed paths before invoking Node.js tools and failing the build if any symbolic link resolves outside the permitted set (Hugo Security Advisory). If upgrading immediately is not possible, restrict repository write and pull request merge access to trusted contributors only, and implement code review processes that specifically check for symlink additions in asset directories. As an additional workaround, disable Node.js tool invocation by configuring security.exec.allow to exclude node, or avoid using css.PostCSS, css.TailwindCSS, and js.Babel features until the upgrade is applied (Hugo Security Advisory). Legitimate symlinks that must point outside the project tree can be explicitly permitted by adding their targets to security.node.permissions.allowRead in the Hugo security configuration.

Community reactions

The vulnerability was credited to researcher DONG2209, who was acknowledged as the finder in the official Hugo security advisory (Hugo Security Advisory). The advisory was published by Hugo maintainer bep and rated as Moderate severity in the project's own advisory, though NVD and GitHub Advisory Database classify it as High based on CVSS v4.0 scoring. No significant broader media coverage or notable social media discussion has been identified at this time.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

hugo

Fixed

sid

hugo: 0.166.0-1

Fixed

trixie

hugo

Fixed

Ubuntu

Unknown

bionic (esm-apps)

hugo

Unknown

devel

hugo

Unknown

focal (esm-apps)

hugo

Unknown

jammy

hugo

Unknown

jammy (esm-apps)

hugo

Unknown

noble

hugo

Unknown

noble (esm-apps)

hugo

Unknown

resolute

hugo

Unknown

RHEL / CentOS

Affected

RHEL 10

Not Affected

Alpine

Affected

edge

0.164.0-r0

Affected

Source: This report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-100702HIGH8.2
  • Grafana logoGrafana
  • grafana.src
NoYesSep 26, 2026
CVE-2026-102276HIGH7.5
  • JavaScript logoJavaScript
  • sgx-enclave-latest-tdqe-unsigned
NoYesSep 28, 2026
CVE-2026-100701MEDIUM6
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-81841MEDIUM5.3
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesSep 29, 2026
CVE-2026-81842MEDIUM4.3
  • Grafana logoGrafana
  • grafana
NoYesSep 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management