HIGH8.1CVE-2026-44301Hugo's Node tool execution allows file system access outside the project directory from 0
MEDIUM6.8CVE-2026-58404Hugo: security.http.urls deny rules bypassed by alternate IPv4 encodings (SSRF) from 0
MEDIUM6.5CVE-2026-58403Hugo: Symlink confinement bypass in os.ReadFile from 0
MEDIUM6.1Hugo: XSS via text/html content files in github.com/gohugoio/hugo
from 0
MEDIUM6.1Hugo Markdown titles are not escaped in internal render hooks in github.com/gohugoio/hugo
from 0, < 0.125.4-1
MEDIUM5.8Hugo: security.http.urls allow-list bypass via HTTP redirects in github.com/gohugoio/hugo
from 0
MEDIUM5.5Hugo: Symlink confinement bypass in resources.Get in github.com/gohugoio/hugo
from 0
MEDIUM5.4Hugo: XSS via unescaped code-fence language in default code block renderer
from 0
—Hugo does not escape some attributes in internal templates in github.com/gohugoio/hugo
from 0