
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-100692 is a symlink traversal vulnerability (CWE-59) in Hugo, the open-source static site generator, that allows unauthenticated attackers to read arbitrary files from the build system during site generation. Affecting Hugo versions after v0.123.0 and before v0.166.0, the flaw enables a malicious theme or vendored module to place a symlink at a mount root (e.g., themes/mytheme/assets -> /some/dir/outside), bypassing Hugo's intended confinement that restricts theme/module mounts to local paths. The vulnerability was published on September 26, 2026, and credited to researcher DONG2209. It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, Github Advisory).
The root cause is improper link resolution before file access (CWE-59): Hugo's symlink confinement logic checked whether a path was within the mount root boundary, but failed to verify whether the mount root itself — or intermediate directories between the mount root and the module directory — was a symlink pointing outside the project. This allowed a theme or vendored module stored in themes/ to include a symlink at the mount root level (e.g., themes/mytheme/assets -> /etc/ or another sensitive directory), which Hugo would then follow during build operations such as resources.Get, resources.Match, and static mount publishing to public/. Modules fetched via Go modules are not affected because Go module zip archives cannot contain symlinks by design. The attack requires the ability to commit or supply a malicious theme or vendored module to the target Hugo project (GitHub Advisory, Github Advisory).
Successful exploitation allows an attacker who can introduce a malicious theme or vendored module into a Hugo project to read arbitrary files from the build system — including sensitive configuration files, credentials, or private data — and potentially publish them to the generated public/ output directory, making them publicly accessible. The impact is limited to confidentiality (no integrity or availability impact), but the exposed files could include secrets, environment variables, or other sensitive build-system content. This is particularly relevant in CI/CD pipelines where Hugo builds are automated and the build environment may contain sensitive credentials (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the ability to commit a malicious theme or vendored module to the target repository, which limits the attack surface to supply-chain scenarios or cases where untrusted themes are used (GitHub Advisory, Github Advisory).
themes/mytheme/) and replace a mount-root directory (e.g., themes/mytheme/assets) with a symlink pointing to a sensitive directory outside the project root (e.g., ln -s /etc themes/mytheme/assets or ln -s /home/user/.ssh themes/mytheme/assets).resources.Get, resources.Match, or static mounts.public/ output directory, then retrieve them from the published site or build artifacts (GitHub Advisory).themes/ (e.g., themes/<themename>/assets, themes/<themename>/static) pointing to paths outside the project root; symlinks in vendored module directories under vendor/ pointing to external paths.public/ output directory that correspond to system files (e.g., /etc/passwd, SSH keys, .env files) or files from outside the project directory.resources.Get or resources.Match operations.Upgrade Hugo to v0.166.0 or later, where symlinked mount roots and symlinked directories between the mount root and the module directory are treated as non-existent for all modules, including the main project. As a workaround for environments that cannot immediately upgrade, manually inspect themes/ and vendored module directories for symlinks at mount roots before running any build (e.g., using find themes/ -maxdepth 3 -type l), and replace any such symlinks with explicit mount configurations in hugo.toml. Modules fetched via Go modules do not require remediation as they cannot contain symlinks (GitHub Advisory, Github Advisory).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
hugo
devel
hugo
focal (esm-apps)
hugo
jammy
hugo
jammy (esm-apps)
hugo
noble
hugo
noble (esm-apps)
hugo
resolute
hugo
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."