CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100691

MEDIUMCVSS 5.4NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `href` attributes of the generated line-number markup. A crafted `l

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100691 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100691

MEDIUMCVSS 5.4NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `href` attributes of the generated line-number markup. A crafted `l

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]