JLSEC-2026-792

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-792.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-792.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-792
Upstream
  • EUVD-2026-19414
Published
2026-07-25T03:41:43.685Z
Modified
2026-07-25T03:50:07.612321676Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Hugo: Certain markdown links are not properly escaped
Details

Impact

Links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected.

Patches

Patched in v0.159.2

Workarounds

Create custom render hooks for links and images in a Hugo theme/project.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "id": "CVE-2026-35166",
            "published": "2026-04-06T18:16:43.060Z",
            "imported": "2026-07-24T13:46:36.614Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-35166",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35166",
            "modified": "2026-06-17T10:40:08.463Z",
            "database_specific": {
                "status": "Analyzed"
            }
        },
        {
            "id": "GHSA-mcv8-8m8x-48pg",
            "html_url": "https://github.com/advisories/GHSA-mcv8-8m8x-48pg",
            "imported": "2026-07-24T13:46:39.135Z",
            "url": "https://api.github.com/advisories/GHSA-mcv8-8m8x-48pg",
            "modified": "2026-04-06T23:42:25Z",
            "published": "2026-04-03T23:38:19Z"
        },
        {
            "id": "EUVD-2026-19414",
            "published": "2026-04-06T17:37:05Z",
            "imported": "2026-07-24T13:46:37.732Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-19414",
            "modified": "2026-04-06T18:02:37Z",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19414"
        }
    ]
}
References
Credits

Affected packages

Julia / Hugo_jll

Package

Name
Hugo_jll
Purl
pkg:julia/Hugo_jll?uuid=c8420254-0ddf-5525-a2d3-3ad9242def7d

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.163.3+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-792.json"