CVE-2026-50135Disclosure(gohugo / hugo)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows symlinks) instead of  Lstat , so a direct  resources.Get  of a symlink pointing outside its mount returned the target's contents — letting a symlink planted in a local mount (e.g. a vendored  themes/  theme) read arbitrary files accessible to the Hugo user. Go-module themes from GitHub (symlinks stripped) and directory walks were unaffected. Fixed in 0.162.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hugo

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
hugo

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-19: 1Technical Details · 2026-06-19: 106-19
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve
    Disclosure

    🟠 Hugo, Symlink Confinement Bypass, #CVE-2026-50135 (Medium) -DC-Jun2026-486 https://dailycve.com/hugo-symlink-confinement-bypass-cve-2026-50135-medium-dc-jun2026-486/

    Post summary

    A medium‑severity CVE (CVE‑2026‑50135) for Hugo’s symlink confinement bypass has been announced, but no PoC, exploit code, mitigation, or evidence of active exploitation is presented.

    0000036
    213 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgohugohugo---

Explore more