Vulnerability Description
Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows symlinks) instead of Lstat , so a direct resources.Get of a symlink pointing outside its mount returned the target's contents — letting a symlink planted in a local mount (e.g. a vendored themes/ theme) read arbitrary files accessible to the Hugo user. Go-module themes from GitHub (symlinks stripped) and directory walks were unaffected. Fixed in 0.162.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gohugo | Hugo | >= 0.123.0, < 0.161.1 |
Related Weaknesses (CWE)
References
- https://github.com/gohugoio/hugo/commit/f8b5fa09a64950c32b803821ede411ebfe772b7aPatch
- https://github.com/gohugoio/hugo/releases/tag/v0.162.0ProductRelease Notes
- https://github.com/gohugoio/hugo/security/advisories/GHSA-fw87-fv5r-9fpwPatchVendor Advisory
FAQ
What is CVE-2026-50135?
CVE-2026-50135 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows symlinks) instead of Lstat , so a direct resources.Get of a symlink pointing...
How severe is CVE-2026-50135?
CVE-2026-50135 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-50135?
Check the references section above for vendor advisories and patch information. Affected products include: Gohugo Hugo.