
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-100691 is a stored cross-site scripting (XSS) vulnerability in the Hugo static site generator affecting versions 0.75.0 through 0.165.x. The flaw exists in Hugo's syntax highlighter, which fails to HTML-escape the lineAnchors option before passing it to the Chroma library, resulting in the value being written verbatim into id and href attributes of generated line-number markup. This allows a contributor with Markdown authoring access to inject arbitrary JavaScript that executes in the browsers of all site visitors. It was disclosed on September 26, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Github Advisory DB).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically a failure to sanitize the lineAnchors parameter before it is forwarded to the Chroma syntax highlighting library. When a Markdown code fence includes attributes such as lineNos=true anchorLineNos=true lineAnchors="z\">alert(1)", Hugo passes the raw value directly into the id and href HTML attributes of generated line-number anchor tags without escaping, resulting in injected HTML/JavaScript in the rendered static output. Exploitation requires the attacker to have contributor-level access to submit Markdown content, and a site visitor must load the affected page (stored XSS). The highlight template function is equally affected when supplied an untrusted lineAnchors value (GitHub Advisory, Github Advisory DB).
Successful exploitation allows an authenticated contributor to persistently inject arbitrary JavaScript into Hugo-generated static pages, which then executes in the browsers of all visitors who view those pages. The primary impacts are low-level confidentiality exposure (e.g., session token theft, credential harvesting) and integrity compromise of the rendered site content in visitors' browsers. Availability of the Hugo server itself is not affected, and the vulnerability does not directly enable server-side code execution or lateral movement within backend infrastructure (Github Advisory DB, GitHub Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the disclosure date. The EPSS score is 0.0, indicating very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for contributor-level access to submit Markdown content to the affected Hugo site (Github Advisory DB, GitHub Advisory).
lineAnchors attribute, for example:```go {lineNos=true anchorLineNos=true lineAnchors="z\">alert(document.cookie)"}
func main() {}
```lineAnchors value embedded verbatim in id and href attributes of line-number anchor tags.id or href attributes of <a> tags inside line-number markup (e.g., id="z"><script> or href="#z"><img onerror=).lineAnchors values that include HTML special characters such as ", >, <, or JavaScript event handlers.lineAnchors values; web server access logs showing requests to pages with syntax-highlighted code blocks from unfamiliar contributor accounts.The vulnerability is fixed in Hugo version 0.166.0, where the lineAnchors value is HTML-escaped before being passed to Chroma. All users running Hugo 0.75.0 through 0.165.x should upgrade to 0.166.0 or later immediately. No configuration-based workaround exists; if upgrading is not immediately possible, the only mitigation is to restrict Markdown submission to trusted contributors only and avoid processing untrusted Markdown content (GitHub Advisory, Github Advisory DB).
The advisory was published by Hugo maintainer bep on September 9, 2026, and credited researcher DONG2209 as the finder. The vulnerability was classified as Moderate severity, consistent with Hugo's security model that treats content as trusted input — the advisory explicitly notes it is published for sites that nonetheless process untrusted Markdown. No significant broader media coverage or notable community controversy has been observed (GitHub Advisory).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
hugo
devel
hugo
focal (esm-apps)
hugo
jammy
hugo
jammy (esm-apps)
hugo
noble
hugo
noble (esm-apps)
hugo
resolute
hugo
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."