{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-100693/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hugo:hugo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-100690"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Hugo (0.161.0-0.165.0)","Hugo (v0.162.0 - v0.165.x)","Hugo (\u003e 0.123.0, \u003c 0.166.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","static-site-generator","webserver","cve-2026-100693","hugo"],"_cs_type":"advisory","_cs_vendors":["Hugo"],"content_html":"\u003cp\u003eHugo versions 0.161.0 through v0.165.0 are affected by a directory traversal vulnerability that stems from improper validation of symbolic links within the integrated Node.js sandbox. Hugo utilizes the Node.js permission model to restrict file system access for integrated tools such as PostCSS, TailwindCSS, and Babel. However, because the permission model validates lexical paths rather than resolved paths, Hugo fails to detect when symbolic links point outside of the project directory or configured mounts. An attacker with the ability to influence project content, such as through a malicious pull request or compromised source repository, can commit a symbolic link that resolves to a sensitive system file (e.g., /etc/passwd). When the project is built, the integrated Node.js tools follow this symlink, potentially disclosing the content of the target file in the resulting site output. This vulnerability is fixed in version v0.166.0, which enforces strict resolution of all paths to ensure they remain within allowed boundaries.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the disclosure of arbitrary files readable by the user account running the Hugo build process. This is particularly critical in CI/CD environments where build processes may have broader read permissions or access to sensitive build-time secrets and environment files. The number of impacted projects depends on the use of Node.js-based Hugo features (PostCSS, TailwindCSS, Babel) and the presence of external contributor access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of all Hugo instances to version v0.166.0 or later to address the symlink resolution logic. For organizations using Hugo in automated pipelines, implement strict file system auditing to detect non-project-relative symbolic links in source repositories prior to the build phase.\u003c/p\u003e\n","date_modified":"2026-09-26T17:00:48Z","date_published":"2026-09-26T15:12:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hugo-symlink-traversal/","summary":"Hugo versions 0.161.0 through 0.165.0 contain a directory traversal vulnerability where the Node.js sandbox fails to resolve symbolic links correctly, allowing unauthorized disclosure of sensitive files during the build process.","title":"CVE-2026-100690: Symlink Traversal Vulnerability in Hugo Node.js Integration","url":"https://feed.craftedsignal.io/briefs/2026-09-hugo-symlink-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-100693","version":"https://jsonfeed.org/version/1.1"}