OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100694

MEDIUM · CVSS 6.1 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Hugo versions from v0.56.0 to v0.165.x are vulnerable to cross-site scripting (XSS) due to the improper rendering of content files mapped to the text/org media type, allowing attackers to inject malicious scripts into generated sites. This vulnerability primarily affects sites that utilize Org export blocks or @@html:...@@ snippets, particularly if they do not fully trust their content sources. Web developers and site administrators using these versions should prioritize upgrading to v0.166.0 or later to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100694
Severity
MEDIUM
CVSS
6.1
EPSS
0.19%

Original NVD Description

Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through unescaped, resulting in cross-site scripting (XSS) in the generated site. An attacker who can supply or influence a content file under /content or the output of a content adapter can inject scripts that execute in the browsers of visitors to the affected pages. Only pages whose source file or content-adapter output declares the text/org media type are affected, and sites that fully trust all content sources are not impacted. Version v0.166.0 fixes the issue by introducing a security.allowContent allowlist that denies text/org by default; sites that intentionally author Org Mode content can opt back in with [security] allowContent = ['.*'].

Related CVEs

Other vulnerabilities affecting the same vendor(s)