CyberRota Analysis
AI-GeneratedHugo versions from v0.123.0 to v0.166.0 are vulnerable due to inadequate symlink confinement checks, allowing symlinks at the mount root to expose sensitive files during site builds. This could lead to unauthorized access to files outside the intended directory structure, potentially compromising the integrity of published content. Organizations using Hugo for static site generation should prioritize updating to v0.166.0 or later to mitigate this risk, and consider inspecting their themes and modules for symlinks as an immediate workaround.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a mount root (for example themes/mytheme/assets -> /some/dir/outside). Files behind such a symlink were readable during a site build through resources.Get, resources.Match and similar functions, and could be published to public/ via static mounts, bypassing the rule that theme and module mount sources must be local paths. Modules fetched via Go modules are not affected because Go module zips cannot contain symlinks, and this is not an escalation for the main project, which may already mount absolute paths by configuration. Fixed in v0.166.0, where symlinked mount roots and symlinked directories between the mount root and the module directory are treated as non-existent for all modules. As a workaround, inspect themes/ and vendored modules for symlinks at mount roots before building, or replace symlinks with explicit mounts.
Related CVEs
Other vulnerabilities affecting the same vendor(s)