CyberRota Analysis
AI-GeneratedHugo versions from v0.56.0 to v0.165.x are vulnerable to cross-site scripting (XSS) due to the improper rendering of content files mapped to the text/org media type, allowing attackers to inject malicious scripts into generated sites. This vulnerability primarily affects sites that utilize Org export blocks or @@html:...@@ snippets, particularly if they do not fully trust their content sources. Web developers and site administrators using these versions should prioritize upgrading to v0.166.0 or later to mitigate the risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through unescaped, resulting in cross-site scripting (XSS) in the generated site. An attacker who can supply or influence a content file under /content or the output of a content adapter can inject scripts that execute in the browsers of visitors to the affected pages. Only pages whose source file or content-adapter output declares the text/org media type are affected, and sites that fully trust all content sources are not impacted. Version v0.166.0 fixes the issue by introducing a security.allowContent allowlist that denies text/org by default; sites that intentionally author Org Mode content can opt back in with [security] allowContent = ['.*'].
Related CVEs
Other vulnerabilities affecting the same vendor(s)