CVE-2026-35166

EUVD-2026-19414
Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected. This vulnerability is fixed in 0.159.2.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Affected Products (NVD)
VendorProductVersion
gohugohugo
0.60.0 ≤
𝑥
< 0.159.2
gohugohugo
0.60.0 ≤
𝑥
< 0.159.2
gohugohugo
0.60.0 ≤
𝑥
< 0.159.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
hugo
bookworm
no-dsa
bullseye
postponed
bullseye (security)
vulnerable
forky
0.161.1-1
fixed
sid
0.161.1-1
fixed
trixie
no-dsa