Description
Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place — or who convinces a site author to place — a symlink inside a mounted directory (for example, in a locally vendored theme under themes/) can cause functions that perform direct lookups, such as resources.Get and os.ReadFile, to follow that symlink and read files outside the intended project boundaries, disclosing their contents in the built site. Themes mounted as Go modules fetched from GitHub have symlinks stripped on download and are not affected, and multi-directory walks (e.g. content/asset walking) are not affected. This issue is an incomplete-fix follow-up to GHSA-c3wq-j5vh-68rc and GHSA-fw87-fv5r-9fpw; it is fixed in v0.165.0.
Published: 2026-09-11
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

Hugo versions after 0.123.0 and before 0.165.0 allow directory symlinks in mounted directories to be resolved during direct resource lookups, such as resources.Get or os.ReadFile. An attacker who can place a symlink inside a mounted theme folder (for example, themes/ or other vendor directories) can cause Hugo to follow that link and read files outside the intended project boundaries, resulting in disclosure of potentially sensitive files in the generated site. This vulnerability represents a classic path‑confinement bypass (CWE‑59).

Affected Systems

The issue affects the gohugoio Hugo static site generator, specifically releases between v0.123.0 (exclusive) and v0.165.0 (exclusive). Users running these versions that utilize local or externally mounted themes with symlinks are subject to the flaw. Themes fetched as Go modules from GitHub automatically strip symlinks during download and are not impacted, nor are multi‑directory walks performed by the content/asset system.

Risk and Exploitability

The CVSS score of 9.3 places this vulnerability in the critical category. The EPSS score is not available, but the fact that KEV catalog does not reduce its potential impact. An attacker needs the ability to create or influence a symlink in a mounted directory, which can be achieved through supply‑chain manipulation or the attacker can read arbitrary files from the build environment, exposing credentials, configuration files, or other confidential data during site generation. The risk remains high until the product is updated to the fixed v0.165.0 release.

Generated by OpenCVE AI on September 11, 2026 at 14:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Hugo v0.165.0 or later, which implements proper symlink confinement.
  • If an upgrade is not immediately feasible, manually audit any mounted directories or themes for symlinks that point outside the project, removing them or replacing the theme with a copy that has no symlinks.
  • Run the site generation in a minimal‑privilege environment where the build user is only allowed read access to the expected source directories, ensuring that even if a symlink were accidentally present it would not resolve to sensitive locations.

Generated by OpenCVE AI on September 11, 2026 at 14:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 11 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place — or who convinces a site author to place — a symlink inside a mounted directory (for example, in a locally vendored theme under themes/) can cause functions that perform direct lookups, such as resources.Get and os.ReadFile, to follow that symlink and read files outside the intended project boundaries, disclosing their contents in the built site. Themes mounted as Go modules fetched from GitHub have symlinks stripped on download and are not affected, and multi-directory walks (e.g. content/asset walking) are not affected. This issue is an incomplete-fix follow-up to GHSA-c3wq-j5vh-68rc and GHSA-fw87-fv5r-9fpw; it is fixed in v0.165.0.
Title Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get
First Time appeared Gohugo
Gohugo hugo
Weaknesses CWE-59
CPEs cpe:2.3:a:gohugo:hugo:*:*:*:*:*:*:*:*
Vendors & Products Gohugo
Gohugo hugo
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T12:18:15.839Z

Reserved: 2026-09-11T10:51:59.215Z

Link: CVE-2026-89258

cve-icon Vulnrichment

Updated: 2026-09-11T12:18:12.062Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:56.310

Modified: 2026-09-11T15:21:12.850

Link: CVE-2026-89258

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T11:15:34Z

Links: CVE-2026-89258 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T19:00:15Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')