Vulnerability Description
Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (typically .html files under /content, or pages produced by a content adapter that sets content.mediaType = "text/html") had their body emitted verbatim into the rendered page. A site that ingests HTML content from an untrusted source could therefore be served stored cross-site scripting. This vulnerability is fixed in 0.162.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gohugo | Hugo | < 0.162.0 |
Related Weaknesses (CWE)
References
- https://github.com/gohugoio/hugo/commit/e41a06447daa3071a01f333fdcec0a5153c3c8d1Patch
- https://github.com/gohugoio/hugo/releases/tag/v0.162.0Release Notes
- https://github.com/gohugoio/hugo/security/advisories/GHSA-c54g-xjwj-8g82Vendor Advisory
FAQ
What is CVE-2026-50133?
CVE-2026-50133 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (typically .html files under /content, or pages produc...
How severe is CVE-2026-50133?
CVE-2026-50133 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-50133?
Check the references section above for vendor advisories and patch information. Affected products include: Gohugo Hugo.