Impact
Hugo versions after 0.123.0 and before 0.165.0 allow directory symlinks in mounted directories to be resolved during direct resource lookups, such as resources.Get or os.ReadFile. An attacker who can place a symlink inside a mounted theme folder (for example, themes/ or other vendor directories) can cause Hugo to follow that link and read files outside the intended project boundaries, resulting in disclosure of potentially sensitive files in the generated site. This vulnerability represents a classic path‑confinement bypass (CWE‑59).
Affected Systems
The issue affects the gohugoio Hugo static site generator, specifically releases between v0.123.0 (exclusive) and v0.165.0 (exclusive). Users running these versions that utilize local or externally mounted themes with symlinks are subject to the flaw. Themes fetched as Go modules from GitHub automatically strip symlinks during download and are not impacted, nor are multi‑directory walks performed by the content/asset system.
Risk and Exploitability
The CVSS score of 9.3 places this vulnerability in the critical category. The EPSS score is not available, but the fact that KEV catalog does not reduce its potential impact. An attacker needs the ability to create or influence a symlink in a mounted directory, which can be achieved through supply‑chain manipulation or the attacker can read arbitrary files from the build environment, exposing credentials, configuration files, or other confidential data during site generation. The risk remains high until the product is updated to the fixed v0.165.0 release.
OpenCVE Enrichment