CVE-2026-50135: Gohugo Hugo

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows symlinks) instead of  Lstat , so a direct  resources.Get  of a symlink pointing outside its mount returned the target's contents — letting a symlink planted in a local mount (e.g. a vendored  themes/  theme) read arbitrary files accessible to the Hugo user. Go-module themes from GitHub (symlinks stripped) and directory walks were unaffected. Fixed in 0.162.0.

Affected products

  • Gohugo Hugo: from 0.123.0, before 0.161.1 (fixed in 0.161.1)

Published 2026-07-06. Last modified 2026-07-08.