Impact
Affected versions of the Hugo static site generator enable Node tools to execute under the Node permission model, yet the default security.exec.allow list still includes TailwindCSS. TailwindCSS requires highly permissive flags (--allow-addons, --allow-child-process, --allow-worker) that allow a Node tool invoked during site build to read and write arbitrary files outside the project's working directory. This bypasses the restriction introduced to mitigate other privilege escalation problems, permitting an attacker to tamper with or ex in uncontrolled file system access.
Affected Systems
Any deployments of Hugo built with a version newer than 0.43 and older than 0.165.0 that include TailwindCSS in vendor is gohugoio and the product is Hugo, a static site generator written in Go. Versions 0.165.0 and later have list, eliminating the issue.
Risk and Exploitability
The CVSS score of 9.3 indicates critical impact for authenticity, confidentiality, and availability. EPSS data is not available, so while potential for exploitation is high, the exact likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation yet. Likely attack vectors involve an adversary supplying a malicious Hugo configuration or template that builds a site, triggering the Node tool execution with permissive flags, allowing arbitrary file access. Successful exploitation would require the attacker to control or influence the Hugo build process.
OpenCVE Enrichment