Bug 2497463 (CVE-2026-50133) - CVE-2026-50133 github.com/gohugoio/hugo: Hugo: Cross-site Scripting via untrusted HTML content files
Summary: CVE-2026-50133 github.com/gohugoio/hugo: Hugo: Cross-site Scripting via untru...
Keywords:
Status: NEW
Alias: CVE-2026-50133
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-06 20:02 UTC by OSIDB Bzimport
Modified: 2026-07-28 06:52 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-06 20:02:41 UTC
Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (typically .html files under /content, or pages produced by a content adapter that sets content.mediaType = "text/html") had their body emitted verbatim into the rendered page. A site that ingests HTML content from an untrusted source could therefore be served stored cross-site scripting. This vulnerability is fixed in 0.162.0.


Note You need to log in before you can comment on or make changes to this bug.