CVE-2026-50135
EUVD-2026-4192206.07.2026, 21:16
Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows symlinks) instead of Lstat , so a direct resources.Get of a symlink pointing outside its mount returned the target's contents — letting a symlink planted in a local mount (e.g. a vendored themes/ theme) read arbitrary files accessible to the Hugo user. Go-module themes from GitHub (symlinks stripped) and directory walks were unaffected. Fixed in 0.162.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gohugo | hugo | 0.123.0 ≤ 𝑥 < 0.161.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases