Threat intelligence dashboard
CVE-2026-100691medium

Hugo before 0.166.0 Stored XSS via lineAnchors code block option

Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `href` attributes of the generated line-number markup. A crafted `lineAnchors` value supplied as a Markdown code fence attribute (or passed to the `highlight` template function) results in unescaped HTML in the rendered page, allowing arbitrary JavaScript to execute in the browsers of visitors to the generated site. This affects sites that build and publish Markdown from untrusted contributors; Hugo's security model otherwise considers content trusted input. Fixed in 0.166.0, where the `lineAnchors` value is HTML-escaped before being passed to Chroma.

Risk score

5.1

CVSS 4.0

Vendor
gohugoio
Product
hugo
CWE
CWE-79
Published
Sep 26, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

hugo

gohugoio

Version / rangeStatusType
0.75.0 to before 0.166.0affectedsemver
0.166.0unaffectedsemver

Technical metrics

5.1

CVSS 4.0

Severity
medium
Source
VulnCheck
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

5.4

CVSS 3.1

Severity
medium
Source
VulnCheck
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N