{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3agohugohugo/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gohugo:hugo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-89259"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Hugo (\u003e= 0.43, \u003c 0.165.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","supply-chain","static-site-generator"],"_cs_type":"advisory","_cs_vendors":["Hugo"],"content_html":"\u003cp\u003eHugo, a popular static site generator, introduced a vulnerability in versions 0.43 through 0.164.0 due to an overly permissive default configuration. The application's \u003ccode\u003esecurity.exec.allow\u003c/code\u003e list included TailwindCSS, which necessitates highly permissive Node.js runtime flags, specifically --allow-addons, --allow-child-process, and --allow-worker. Because these flags were implicitly enabled for TailwindCSS within the Hugo build process, any malicious or compromised Node-based tool invoked during site generation could bypass security sandboxing intended to limit execution scope. This flaw allows an attacker to manipulate the build process to perform arbitrary file reads and writes outside of the project's intended working directory. This vulnerability was addressed in Hugo version 0.165.0 by removing TailwindCSS from the default allowed execution list.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to achieve unauthorized file system access on the machine performing the build. In CI/CD environments where Hugo is used to generate documentation or site content, this could lead to the exfiltration of sensitive source code, configuration secrets, or the injection of malicious content into the final static site artifacts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Hugo to version 0.165.0 or later to ensure TailwindCSS is removed from the default allowed execution list.\u003c/li\u003e\n\u003cli\u003eFor users unable to upgrade, manually override the configuration by defining a restrictive \u003ccode\u003esecurity.exec.allow\u003c/code\u003e list in the \u003ccode\u003ehugo.toml\u003c/code\u003e file to explicitly exclude unnecessary or insecure tools.\u003c/li\u003e\n\u003cli\u003eAudit build logs for CI/CD pipelines to identify if Node-based tools are being executed with unexpected flags or accessing paths outside the project root.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-11T13:12:55Z","date_published":"2026-09-11T13:12:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hugo-exec-bypass/","summary":"Hugo versions 0.43 through 0.164.0 include TailwindCSS in the default allowed execution list, enabling Node-based tools to bypass sandbox restrictions and perform unauthorized file read/write operations.","title":"Arbitrary File System Access via Hugo Build Process","url":"https://feed.craftedsignal.io/briefs/2026-09-hugo-exec-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:gohugo:hugo:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}