Vulnerability DatabaseCVE-2026-100691

CVE-2026-100691: 
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-100691 is a stored cross-site scripting (XSS) vulnerability in the Hugo static site generator affecting versions 0.75.0 through 0.165.x. The flaw exists in Hugo's syntax highlighter, which fails to HTML-escape the lineAnchors option before passing it to the Chroma library, resulting in the value being written verbatim into id and href attributes of generated line-number markup. This allows a contributor with Markdown authoring access to inject arbitrary JavaScript that executes in the browsers of all site visitors. It was disclosed on September 26, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Github Advisory DB).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a failure to sanitize the lineAnchors parameter before it is forwarded to the Chroma syntax highlighting library. When a Markdown code fence includes attributes such as lineNos=true anchorLineNos=true lineAnchors="z\">alert(1)", Hugo passes the raw value directly into the id and href HTML attributes of generated line-number anchor tags without escaping, resulting in injected HTML/JavaScript in the rendered static output. Exploitation requires the attacker to have contributor-level access to submit Markdown content, and a site visitor must load the affected page (stored XSS). The highlight template function is equally affected when supplied an untrusted lineAnchors value (GitHub Advisory, Github Advisory DB).

Impact

Successful exploitation allows an authenticated contributor to persistently inject arbitrary JavaScript into Hugo-generated static pages, which then executes in the browsers of all visitors who view those pages. The primary impacts are low-level confidentiality exposure (e.g., session token theft, credential harvesting) and integrity compromise of the rendered site content in visitors' browsers. Availability of the Hugo server itself is not affected, and the vulnerability does not directly enable server-side code execution or lateral movement within backend infrastructure (Github Advisory DB, GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the disclosure date. The EPSS score is 0.0, indicating very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for contributor-level access to submit Markdown content to the affected Hugo site (Github Advisory DB, GitHub Advisory).

Exploitation steps

  1. Gain contributor access: Obtain permission to submit or edit Markdown content on a Hugo-based site that accepts contributions from untrusted users (e.g., a documentation site, blog, or wiki with open contributions).
  2. Craft malicious Markdown: Create a Markdown file containing a code fence with a weaponized lineAnchors attribute, for example:
    ```go {lineNos=true anchorLineNos=true lineAnchors="z\">alert(document.cookie)"}
    func main() {}
    ```
  3. Submit the content: Commit or upload the malicious Markdown file to the Hugo site's content repository or CMS.
  4. Trigger site build: Wait for or trigger a Hugo site rebuild, which processes the Markdown and generates static HTML with the unescaped lineAnchors value embedded verbatim in id and href attributes of line-number anchor tags.
  5. Payload execution: When any site visitor navigates to the page containing the malicious code block, the injected JavaScript executes in their browser, enabling session hijacking, credential theft, or further malicious actions (GitHub Advisory).

Indicators of compromise

  • File System: Hugo-generated HTML files containing unexpected JavaScript within id or href attributes of <a> tags inside line-number markup (e.g., id="z"><script> or href="#z"><img onerror=).
  • Source Content: Markdown files in the content repository with code fences containing lineAnchors values that include HTML special characters such as ", >, <, or JavaScript event handlers.
  • Logs: Hugo build logs showing code fence attributes with unusual or encoded lineAnchors values; web server access logs showing requests to pages with syntax-highlighted code blocks from unfamiliar contributor accounts.
  • Browser/Client: Unexpected outbound network requests from visitor browsers to attacker-controlled domains originating from Hugo-generated pages with code blocks (GitHub Advisory).

Mitigation and workarounds

The vulnerability is fixed in Hugo version 0.166.0, where the lineAnchors value is HTML-escaped before being passed to Chroma. All users running Hugo 0.75.0 through 0.165.x should upgrade to 0.166.0 or later immediately. No configuration-based workaround exists; if upgrading is not immediately possible, the only mitigation is to restrict Markdown submission to trusted contributors only and avoid processing untrusted Markdown content (GitHub Advisory, Github Advisory DB).

Community reactions

The advisory was published by Hugo maintainer bep on September 9, 2026, and credited researcher DONG2209 as the finder. The vulnerability was classified as Moderate severity, consistent with Hugo's security model that treats content as trusted input — the advisory explicitly notes it is published for sites that nonetheless process untrusted Markdown. No significant broader media coverage or notable community controversy has been observed (GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

hugo

Affected

sid

hugo: 0.166.0-1

Fixed

trixie

hugo

Affected

Ubuntu

Unknown

bionic (esm-apps)

hugo

Unknown

devel

hugo

Unknown

focal (esm-apps)

hugo

Unknown

jammy

hugo

Unknown

jammy (esm-apps)

hugo

Unknown

noble

hugo

Unknown

noble (esm-apps)

hugo

Unknown

resolute

hugo

Unknown

RHEL / CentOS

Affected

RHEL 10

grafana.src

Affected

Alpine

Affected

edge

0.139.0-r0

Affected

v3.24

0.160.1-r1

Affected

Source: This report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-100702HIGH8.2
  • Grafana logoGrafana
  • grafana.src
NoYesSep 26, 2026
CVE-2026-102276HIGH7.5
  • JavaScript logoJavaScript
  • sgx-enclave-latest-tdqe-unsigned
NoYesSep 28, 2026
CVE-2026-100701MEDIUM6
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-81841MEDIUM5.3
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesSep 29, 2026
CVE-2026-81842MEDIUM4.3
  • Grafana logoGrafana
  • grafana
NoYesSep 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management