Medium severity5.4NVD Advisory· Published Jul 6, 2026· Updated Jul 8, 2026
CVE-2026-58402
CVE-2026-58402
Description
Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string into the code class="language-…" data-lang="…" wrapper without HTML escaping. A fence info-string containing a quote and a script payload breaks out of the attribute and injects a live script element. This issue is fixed in 0.163.3.
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/gohugoio/hugo/commit/ce1a7e0bce3713af40496ded3c2c0ceeed49231dnvdPatch
- github.com/gohugoio/hugo/security/advisories/GHSA-q76j-gcg9-vxc6nvdVendor Advisory
- github.com/gohugoio/hugo/pull/15051nvdIssue Tracking
- github.com/gohugoio/hugo/releases/tag/v0.163.3nvdRelease Notes
News mentions
0No linked articles in our index yet.