Hugo is a static site generator that, despite a narrow product footprint, sits in content-pipeline workflows where it processes user-supplied markdown and templates. The observed vulnerability classes—path traversal, cross-site scripting, and OS command injection—reflect the input-handling and template-rendering surface inherent to tools that transform untrusted markup into publishable HTML. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gohugo over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-58403MEDIUM Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files under a mount cannot reach outside the mount tree, but a regres | Jul 6, 2026 | 6.5 | 29 | NO | NO |
CVE-2026-50133MEDIUM Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (typically .html files under /cont | Jul 6, 2026 | 6.1 | 28 | NO | NO |
CVE-2026-58404MEDIUM Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals, but | Jul 6, 2026 | 6.8 | 28 | NO | NO |
CVE-2026-50135MEDIUM Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows symlinks) instead of Lstat , so a direct resources.Get o | Jul 6, 2026 | 5.5 | 27 | NO | NO |
CVE-2026-50134MEDIUM Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL it is called with, but it did not re-validate intermediate UR | Jul 6, 2026 | 5.8 | 27 | NO | NO |
CVE-2026-44301HIGH Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipelines (PostCSS, Babel, TailwindCSS), Hugo invoked the configu | May 12, 2026 | 8.1 | 27 | NO | NO |
CVE-2026-58402MEDIUM Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string into the code class="language-… | Jul 6, 2026 | 5.4 | 26 | NO | NO |
CVE-2020-26284HIGH Hugo is a fast and Flexible Static Site Generator built in Go. Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc documents if these binaries are fou | Dec 21, 2020 | 8.5 | 26 | NO | NO |
CVE-2026-35166MEDIUM Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their | Apr 6, 2026 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gohugo.
Media articles that mention a CVE ID that affects a product developed by Gohugo — matched by CVE ID, not by vendor name.