Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown for links and images not escaped in internal render hooks. Hugo users who are impacted are those who have these hooks enabled and do not trust their Markdown content files. The issue is patched in v0.125.3. As a workaround, replace the templates with user defined templates or disable the internal templates.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-04-23T20:23:42.535Z

Updated: 2024-08-02T02:20:35.602Z

Reserved: 2024-04-19T14:07:11.229Z

Link: CVE-2024-32875

cve-icon Vulnrichment

Updated: 2024-04-29T19:39:07.380Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-23T21:15:48.837

Modified: 2024-04-24T13:39:42.883

Link: CVE-2024-32875

cve-icon Redhat

No data.