OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100690

HIGH · CVSS 7.5 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Hugo versions from v0.161.0 to v0.165.0 are vulnerable due to improper handling of symbolic links within the Node.js permission model, allowing attackers to exploit symlinks to access sensitive files outside the project directory. This vulnerability can lead to unauthorized disclosure of files, including critical system files, if an attacker can contribute content to a Hugo project. Organizations using affected Hugo versions, particularly those that utilize Node.js tools in their build process, should prioritize upgrading to version 0.166.0 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100690
Severity
HIGH
CVSS
7.5
EPSS
0.35%

Original NVD Description

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox. An attacker who can contribute content to a Hugo project (for example via a pull request) can commit a symlink such as assets/css/x.css -> /etc/passwd together with a PostCSS plugin that reads it, allowing any file readable by the Hugo build process to be disclosed and potentially embedded in the published site. This affects builds using the default security configuration; projects that do not invoke Node.js tools are unaffected. Fixed in v0.166.0, which scans allowed paths and fails the build when a symbolic link resolves outside them.

Related CVEs

Other vulnerabilities affecting the same vendor(s)