Description
Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As a result, the restrictions intended by the fix for GHSA-x597-9fr4-5857 could still be bypassed, allowing a Node tool invoked during a build to read and write files outside the project's working directory. Affected versions are those after v0.43; the issue was fixed in v0.165.0 by removing tailwindcss from the default security.exec.allow list. Users who do not use TailwindCSS, or who only build trusted sites, are not affected. As a workaround, users can define a restrictive security.exec.allow list in hugo.toml.
Published: 2026-09-11
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized file access beyond the intended working directory
Action: Immediate Patch
AI Analysis

Impact

Affected versions of the Hugo static site generator enable Node tools to execute under the Node permission model, yet the default security.exec.allow list still includes TailwindCSS. TailwindCSS requires highly permissive flags (--allow-addons, --allow-child-process, --allow-worker) that allow a Node tool invoked during site build to read and write arbitrary files outside the project's working directory. This bypasses the restriction introduced to mitigate other privilege escalation problems, permitting an attacker to tamper with or ex in uncontrolled file system access.

Affected Systems

Any deployments of Hugo built with a version newer than 0.43 and older than 0.165.0 that include TailwindCSS in vendor is gohugoio and the product is Hugo, a static site generator written in Go. Versions 0.165.0 and later have list, eliminating the issue.

Risk and Exploitability

The CVSS score of 9.3 indicates critical impact for authenticity, confidentiality, and availability. EPSS data is not available, so while potential for exploitation is high, the exact likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation yet. Likely attack vectors involve an adversary supplying a malicious Hugo configuration or template that builds a site, triggering the Node tool execution with permissive flags, allowing arbitrary file access. Successful exploitation would require the attacker to control or influence the Hugo build process.

Generated by OpenCVE AI on September 11, 2026 at 14:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Hugo to version 0.165.0, which removes TailwindCSS from the default security.exec.allow list.
  • If immediate upgrade is not feasible, edit hugo.toml to define a restrictive security.exec.allow list that excludes TailwindCSS and limits Node tool execution scripts or third‑party Node tool usage to ensure no permissive TailwindCSS flags are present and that sufficient file access restrictions are enforced.
  • Validate that all Hugo templates, configuration files, and third‑party plugins do not re‑enable permissive TailwindCSS flags or introduce new Node tools, and consider running builds in a separate, read‑only environment to prevent unintended file access.

Generated by OpenCVE AI on September 11, 2026 at 14:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As a result, the restrictions intended by the fix for GHSA-x597-9fr4-5857 could still be bypassed, allowing a Node tool invoked during a build to read and write files outside the project's working directory. Affected versions are those after v0.43; the issue was fixed in v0.165.0 by removing tailwindcss from the default security.exec.allow list. Users who do not use TailwindCSS, or who only build trusted sites, are not affected. As a workaround, users can define a restrictive security.exec.allow list in hugo.toml.
Title Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS
First Time appeared Gohugo
Gohugo hugo
Weaknesses CWE-250
CPEs cpe:2.3:a:gohugo:hugo:*:*:*:*:*:*:*:*
Vendors & Products Gohugo
Gohugo hugo
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T20:29:43.170Z

Reserved: 2026-09-11T10:52:56.668Z

Link: CVE-2026-89259

cve-icon Vulnrichment

Updated: 2026-09-11T17:11:16.147Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:56.480

Modified: 2026-09-24T20:43:32.537

Link: CVE-2026-89259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:15:14Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges