Bug 2541815 (CVE-2026-100690)
| Summary: | CVE-2026-100690 github.com/gohugoio/hugo: Hugo: Arbitrary file read via symbolic link sandbox escape | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | anjoseph, eglynn, jjoyce, jprabhak, jpretori, jschluet, lchilton, lhh, mburns, mgarciac, rhel-process-autobot, sfeifer, watson-tool-maintainers, wtam |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Hugo. This vulnerability allows information disclosure when Hugo executes build tools under the Node.js permission model, which validates only lexical file paths and fails to restrict symbolic links pointing outside the sandbox. An attacker capable of contributing content to a repository can exploit this by committing a symbolic link targeting sensitive host files alongside a build tool that reads it. Consequently, files readable by the build process can be exposed and embedded into the published site.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-26 13:32:15 UTC
|