DEBIAN-CVE-2026-100690

Source
https://security-tracker.debian.org/tracker/CVE-2026-100690
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-100690.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-100690
Upstream
Published
2026-09-26T14:16:53Z
Modified
2026-09-27T05:00:06Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox. An attacker who can contribute content to a Hugo project (for example via a pull request) can commit a symlink such as assets/css/x.css -> /etc/passwd together with a PostCSS plugin that reads it, allowing any file readable by the Hugo build process to be disclosed and potentially embedded in the published site. This affects builds using the default security configuration; projects that do not invoke Node.js tools are unaffected. Fixed in v0.166.0, which scans allowed paths and fails the build when a symbolic link resolves outside them.

References

Affected packages

Debian:12 / hugo

Package

Name
hugo
Purl
pkg:deb/debian/hugo?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.111.3-1
0.112.7-1
0.113.0-1
0.113.0-2
0.113.0-3
0.114.1-1
0.114.1-2
0.115.4-1
0.116.1-1
0.117.0-1
0.118.2-1
0.119.0-1
0.119.0-2
0.120.3-1
0.120.4-1
0.121.1-1
0.121.2-1
0.122.0-1
0.123.3-1
0.123.7-1
0.123.8-1
0.123.8-2
0.124.1-1
0.125.4-1
0.125.5-1
0.125.6-1
0.125.7-1
0.126.1-1
0.126.2-1
0.126.3-1
0.127.0-1
0.128.2-1
0.128.2-2
0.129.0-1
0.129.0-2
0.130.0-1
0.130.0-2
0.131.0-1
0.131.0-2
0.150.0-1
0.150.1-1
0.151.0-1
0.151.1-1
0.151.2-1
0.152.1-1
0.152.2-1
0.153.0-1
0.153.1-1
0.153.1-2
0.153.1-3
0.153.2-1
0.154.1-1
0.154.2-1
0.154.2-2
0.154.3-1
0.154.5-1
0.155.1-1
0.155.2-1
0.155.3-1
0.157.0-1
0.157.0-2
0.157.0-3
0.158.0-1
0.158.0-2
0.158.0-3
0.159.0-1
0.159.1-1
0.159.2-1
0.160.0-1
0.160.0-2
0.160.1-1
0.161.0-1
0.161.1-1
0.162.1-1
0.162.1-2
0.162.1-3
0.162.1-4
0.162.1-5
0.162.1-6
0.162.1-7
0.165.0-1
0.165.0-2
0.165.0-3
0.166.0-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-100690.json"

Debian:13 / hugo

Package

Name
hugo
Purl
pkg:deb/debian/hugo?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.131.0-1
0.131.0-2
0.150.0-1
0.150.1-1
0.151.0-1
0.151.1-1
0.151.2-1
0.152.1-1
0.152.2-1
0.153.0-1
0.153.1-1
0.153.1-2
0.153.1-3
0.153.2-1
0.154.1-1
0.154.2-1
0.154.2-2
0.154.3-1
0.154.5-1
0.155.1-1
0.155.2-1
0.155.3-1
0.157.0-1
0.157.0-2
0.157.0-3
0.158.0-1
0.158.0-2
0.158.0-3
0.159.0-1
0.159.1-1
0.159.2-1
0.160.0-1
0.160.0-2
0.160.1-1
0.161.0-1
0.161.1-1
0.162.1-1
0.162.1-2
0.162.1-3
0.162.1-4
0.162.1-5
0.162.1-6
0.162.1-7
0.165.0-1
0.165.0-2
0.165.0-3
0.166.0-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-100690.json"

Debian:14 / hugo

Package

Name
hugo
Purl
pkg:deb/debian/hugo?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.131.0-1
0.131.0-2
0.150.0-1
0.150.1-1
0.151.0-1
0.151.1-1
0.151.2-1
0.152.1-1
0.152.2-1
0.153.0-1
0.153.1-1
0.153.1-2
0.153.1-3
0.153.2-1
0.154.1-1
0.154.2-1
0.154.2-2
0.154.3-1
0.154.5-1
0.155.1-1
0.155.2-1
0.155.3-1
0.157.0-1
0.157.0-2
0.157.0-3
0.158.0-1
0.158.0-2
0.158.0-3
0.159.0-1
0.159.1-1
0.159.2-1
0.160.0-1
0.160.0-2
0.160.1-1
0.161.0-1
0.161.1-1
0.162.1-1
0.162.1-2
0.162.1-3
0.162.1-4
0.162.1-5
0.162.1-6
0.162.1-7
0.165.0-1
0.165.0-2
0.165.0-3
0.166.0-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-100690.json"