Medium severity5.5GHSA Advisory· Published Jul 6, 2026· Updated Jul 8, 2026
CVE-2026-50135
CVE-2026-50135
Description
Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows symlinks) instead of Lstat , so a direct resources.Get of a symlink pointing outside its mount returned the target's contents — letting a symlink planted in a local mount (e.g. a vendored themes/ theme) read arbitrary files accessible to the Hugo user. Go-module themes from GitHub (symlinks stripped) and directory walks were unaffected. Fixed in 0.162.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/gohugoio/hugoGo | >= 0.123.0, < 0.162.0 | 0.162.0 |
Affected products
4- osv-coords2 versionspkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:golang/github.com/gohugoio/hugo
< 0.0.20260723T184607-160000.1.1+ 1 more
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
- (no CPE)range: >= 0.123.0, < 0.162.0
Patches
Vulnerability mechanics
References
4- github.com/gohugoio/hugo/commit/f8b5fa09a64950c32b803821ede411ebfe772b7anvdPatchWEB
- github.com/gohugoio/hugo/security/advisories/GHSA-fw87-fv5r-9fpwnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-fw87-fv5r-9fpwghsaADVISORY
- github.com/gohugoio/hugo/releases/tag/v0.162.0nvdProductRelease NotesWEB
News mentions
0No linked articles in our index yet.