Vendor
high
advisory
CVE-2026-100690: Symlink Traversal Vulnerability in Hugo Node.js Integration
2 TTPs 1 CVEHugo versions 0.161.0 through 0.165.0 contain a directory traversal vulnerability where the Node.js sandbox fails to resolve symbolic links correctly, allowing unauthorized disclosure of sensitive files during the build process.
Hugo +2
vulnerability
path-traversal
static-site-generator
webserver
cve-2026-100693
2t
1c
high
advisory
Arbitrary File System Access via Hugo Build Process
1 TTP 1 CVEHugo versions 0.43 through 0.164.0 include TailwindCSS in the default allowed execution list, enabling Node-based tools to bypass sandbox restrictions and perform unauthorized file read/write operations.
Hugo
vulnerability
supply-chain
static-site-generator
1t
1c
high
threat
Arbitrary Command Execution in Hugo via TailwindCSS Configuration
2 TTPs 1 CVEHugo versions 0.162.0 through 0.164.0 allowed arbitrary command execution by incorrectly including TailwindCSS in the default Node.js permission sandbox, enabling malicious configurations to spawn unprivileged shell processes.
exploited
Hugo +1
ssrf
supply-chain
static-site-generator
2t
1c
updated