Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string into the code class="language-…" data-lang="…" wrapper without HTML escaping. A fence info-string containing a quote and a script payload breaks out of the attribute and injects a live script element. This issue is fixed in 0.163.3.
{
"license": "CC-BY-4.0",
"sources": [
{
"id": "CVE-2026-58402",
"published": "2026-07-06T20:16:38.040Z",
"imported": "2026-07-24T13:46:36.685Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-58402",
"modified": "2026-07-08T03:06:03.630Z",
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-58402",
"database_specific": {
"status": "Analyzed"
}
},
{
"id": "EUVD-2026-41904",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-41904",
"imported": "2026-07-24T13:46:37.731Z",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-41904",
"published": "2026-07-06T19:19:58Z",
"modified": "2026-07-06T20:54:38Z"
}
]
}