CVE-2026-50135

Name
CVE-2026-50135
Description
Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows symlinks) instead of  Lstat , so a direct  resources.Get  of a symlink pointing outside its mount returned the target's contents — letting a symlink planted in a local mount (e.g. a vendored  themes/  theme) read arbitrary files accessible to the Hugo user. Go-module themes from GitHub (symlinks stripped) and directory walks were unaffected. Fixed in 0.162.0.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/gohugoio/hugo/commit/f8b5fa09a64950c32b803821ede411ebfe772b7a
security-advisories@github.com https://github.com/gohugoio/hugo/releases/tag/v0.162.0
security-advisories@github.com https://github.com/gohugoio/hugo/security/advisories/GHSA-fw87-fv5r-9fpw

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gohugo:hugo:*:*:*:*:*:*:*:* hugo >= 0.123.0 < 0.161.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
hugo edge-community 0.160.1-r1 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.160.1-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.159.0-r1 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.159.0-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.158.0-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.157.0-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.155.3-r3 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.152.2-r3 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.152.2-r2 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.152.2-r1 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.152.2-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.152.1-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.151.0-r1 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.151.0-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.150.0-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.148.2-r2 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.148.2-r1 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.148.2-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.148.1-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.148.0-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.147.9-r1 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.147.9-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.147.7-r1 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.147.7-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.147.2-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.145.0-r2 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.145.0-r1 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.145.0-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.144.0-r1 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.144.0-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.143.0-r1 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.143.0-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.142.0-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.141.0-r1 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.141.0-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.140.1-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo edge-community 0.139.0-r0 Thomas Boerger <thomas@webhippie.de> possibly vulnerable
hugo 3.24-community 0.160.1-r1 Thomas Boerger <thomas@webhippie.de> possibly vulnerable