CyberRota Analysis
AI-GeneratedHugo versions 0.75.0 through 0.165.x are vulnerable to a stored cross-site scripting (XSS) flaw due to improper escaping of the `lineAnchors` option in the syntax highlighter, allowing attackers to inject arbitrary JavaScript into rendered pages. This vulnerability primarily impacts sites that generate Markdown content from untrusted sources, posing a risk to user security and data integrity. Organizations using affected Hugo versions should prioritize updating to version 0.166.0 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `href` attributes of the generated line-number markup. A crafted `lineAnchors` value supplied as a Markdown code fence attribute (or passed to the `highlight` template function) results in unescaped HTML in the rendered page, allowing arbitrary JavaScript to execute in the browsers of visitors to the generated site. This affects sites that build and publish Markdown from untrusted contributors; Hugo's security model otherwise considers content trusted input. Fixed in 0.166.0, where the `lineAnchors` value is HTML-escaped before being passed to Chroma.
Related CVEs
Other vulnerabilities affecting the same vendor(s)