CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100694

MEDIUMCVSS 6.1NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through unescaped, resulting in cross-site scripting (XSS) in the generated site.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100694 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100694

MEDIUMCVSS 6.1NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through unescaped, resulting in cross-site scripting (XSS) in the generated site.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]