These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-89259 is a critical vulnerability in Hugo, a static site generator, affecting versions after v0.43 and before v0.165.0. The issue arises from the execution of Node tools under Node's permission model, which can be bypassed by TailwindCSS, allowing a Node tool invoked during a build to read and write files outside the project's working directory.
CVE-2026-89258 is a critical vulnerability in Hugo, a static site generator, affecting versions between v0.123.0 and before v0.165.0. An attacker can exploit this vulnerability by placing a symlink inside a mounted directory, allowing them to bypass path confinement and read files outside the intended project boundaries. This issue allows functions that perform direct lookups, such as resources.Get and os [truncated]
CVE-2026-10618 is a stored cross-site scripting (XSS) vulnerability in Hugo, a popular static site generator. The vulnerability arises from the improper handling of attribute values in fenced code blocks, allowing an attacker to inject malicious JavaScript code. This issue affects Hugo versions from 0.93.0 to 0.165.0. Users of Hugo, particularly those who enable code fences and do not use the goldmark's u [truncated]
CVE-2026-10582 is a high-severity vulnerability in Hugo's security.http.urls allowlist. An attacker can make the build fetch an internal endpoint and publish the response in the static output. Defenders should assess exposure and prioritize remediation, especially in deployments where Hugo is used to build and publish static sites. The vulnerability has a CVSS score of 8.3 and is considered HIGH severity. [truncated]
CVE-2026-75926 is a critical vulnerability in Hugo, a popular static site generator. The vulnerability arises from the way Hugo handles the TailwindCSS tool, allowing an attacker to execute arbitrary commands on the system performing the build. This is possible because Hugo 0.162.0 added tailwindcss to the AllowChildProcess default in config/security/securityConfig.go, which makes nodePermissionArgs in co [truncated]
A regression in Hugo, a static site generator, from version 0.123.0 to 0.161.1, caused the RootMappingFs.statRoot function to use Stat (which follows symlinks) instead of Lstat. This change allowed a direct resources.Get of a symlink pointing outside its mount to return the target's contents. Consequently, a symlink planted in a local mount, such as a vendored themes/ theme, could be used to read arbitrar [truncated]
A vulnerability in Hugo, a static site generator, was discovered that allows for unauthorized server-side requests. The issue, CVE-2026-58404, exists from version 0.162.0 through 0.163.0 and is fixed in version 0.163.1. This vulnerability allows attackers to bypass security restrictions and access internal services. Users of Hugo static site generator, especially those using versions between 0.162.0 and 0 [truncated]
CVE-2026-58403 is a MEDIUM severity vulnerability in Hugo's virtual filesystem. A regression in Hugo versions from v0.123.0 through v0.163.0 allowed a symlink planted inside a theme or local mount to read arbitrary files reachable to the user running Hugo. This issue is fixed in v0.163.1. The vulnerability was caused by a regression that led to RootMappingFs.statRoot calling Stat, which follows symlinks, [truncated]
A vulnerability in Hugo, a static site generator, allows for code injection via Markdown code-fence language or info-string. The issue, fixed in version 0.163.3, arises from the default code-block renderer writing the Markdown code-fence language or info-string into the code class=language-… data-lang=… wrapper without HTML escaping. A fence info-string containing a quote and a script payload can break ou [truncated]
CVE-2026-50134 is a vulnerability in the Hugo static site generator that allows for a security bypass via HTTP 3xx redirects. The vulnerability exists in versions from 0.91.0 until 0.162.0 of the Hugo software. The resources.GetRemote function enforces security.http.urls on the URL it is called with, but it did not re-validate intermediate URLs on HTTP 3xx redirects. This allows an allowed server or an at [truncated]
CVE-2026-50133 is a stored cross-site scripting vulnerability in Hugo, a static site generator. Prior to version 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type had their body emitted verbatim into the rendered page. A site that ingests HTML content from an untrusted source could therefore be served stored cross-site scripting.