Vulnerabilidades em gohugoio

16 resultados
Análise Vexday

O Hugo apresenta 11 vulnerabilidades conhecidas, com 7 publicadas nos últimos 90 dias, indicando ritmo recente de descobertas. Nenhuma está sob exploração ativa (KEV) ou classificada como crítica, mas a fraqueza dominante é XSS (CWE-79), típica de processadores de conteúdo. O risco atual é moderado e concentrado em cenários onde entrada não confiável é processada.

CVE-2020-26284HIGHHugo can execute a binary from the current directory on WindowsEPSS 1.5%CVE-2024-55601MEDIUMHugo does not escape some attributes in internal templatesEPSS 0.6%CVE-2024-32875MEDIUMHugo doesn't escape markdown title in internal render hooksEPSS 0.5%CVE-2026-58403MEDIUMHugo symlink confinement bypass in os.ReadFileEPSS 0.5%CVE-2026-50135MEDIUMHugo: Symlink confinement bypass in resources.GetEPSS 0.4%CVE-2026-89259CRITICALHugo before v0.165.0 Insufficient Permission Restriction via TailwindCSSEPSS 0.4%CVE-2026-50134MEDIUMHugo: security.http.urls allow-list bypass via HTTP redirectsEPSS 0.4%CVE-2026-58404MEDIUMHugo security.http.urls deny rules bypassed by alternate IPv4 encodingsEPSS 0.4%CVE-2026-50133MEDIUMHugo: XSS via text/html content filesEPSS 0.3%CVE-2026-10582HIGHHugo 0.91.0 through 0.165.0 Server-Side Request Forgery via security.http.urls Lacking Destination Address ValidationEPSS 0.3%CVE-2026-89258CRITICALHugo before v0.165.0 Symlink Confinement Bypass via resources.GetEPSS 0.3%CVE-2026-58402MEDIUMHugo default code block renderer XSS via unescaped code-fence languageEPSS 0.3%CVE-2026-44301MEDIUMHugo: Node tool execution allows file system access outside the project directoryEPSS 0.3%CVE-2026-10618MEDIUMHugo 0.93.0 through 0.165.0 Stored Cross-Site Scripting via Unescaped Code-Fence Attribute ValuesEPSS 0.2%CVE-2026-35166MEDIUMHugo does not properly escape some Markdown linksEPSS 0.2%CVE-2026-75926CRITICALHugo 0.162.0 to 0.164.x - Node Permission Model Bypass via Default TailwindCSS Child-Process GrantEPSS 0.1%