OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100691

MEDIUM · CVSS 5.4 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Hugo versions 0.75.0 through 0.165.x are vulnerable to a stored cross-site scripting (XSS) flaw due to improper escaping of the `lineAnchors` option in the syntax highlighter, allowing attackers to inject arbitrary JavaScript into rendered pages. This vulnerability primarily impacts sites that generate Markdown content from untrusted sources, posing a risk to user security and data integrity. Organizations using affected Hugo versions should prioritize updating to version 0.166.0 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100691
Severity
MEDIUM
CVSS
5.4
EPSS
0.17%
Java

Original NVD Description

Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `href` attributes of the generated line-number markup. A crafted `lineAnchors` value supplied as a Markdown code fence attribute (or passed to the `highlight` template function) results in unescaped HTML in the rendered page, allowing arbitrary JavaScript to execute in the browsers of visitors to the generated site. This affects sites that build and publish Markdown from untrusted contributors; Hugo's security model otherwise considers content trusted input. Fixed in 0.166.0, where the `lineAnchors` value is HTML-escaped before being passed to Chroma.

Related CVEs

Other vulnerabilities affecting the same vendor(s)