
CVE-2026-35166 Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users wh… https://www.cve.org/CVERecord?id=CVE-2026-35166
Post summary
CVE-2026-35166 exposes improper escaping of links and images in Hugo (versions 0.60.0 to 0.159.2), potentially leading to XSS vulnerabilities.
