CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-C3WQ-J5VH-68RC

GHSA-C3WQ-J5VH-68RC: Hugo Symlink Confinement Bypass in os.ReadFile

Amit Schendel
Amit Schendel
Senior Security Researcher

Jun 19, 2026·5 min read·12 visits

Executive Summary (TL;DR)

A directory confinement regression in Hugo's virtual filesystem allows unauthenticated arbitrary file read during build execution via malicious symbolic links placed in templates or themes.

Hugo versions v0.123.0 through v0.163.0 are vulnerable to a directory confinement bypass. A regression in the virtual filesystem layer causes symbolic links to be followed during template execution, allowing templates to read arbitrary host files.

Vulnerability Overview

Hugo relies on a structured virtual filesystem to enforce directory boundaries during compilation. This mechanism prevents custom layouts, theme files, and templates from reading files outside the project repository. It serves as a security boundary to protect sensitive host configurations when rendering untrusted user inputs.

A path resolution regression was introduced in Hugo version v0.123.0 that degrades this security restriction. The vulnerability, tracked under GHSA-C3WQ-J5VH-68RC, allows templates to traverse beyond the designated directory boundaries. By utilizing symbolic links within the project directory, templates can read sensitive system files on the build host.

The vulnerability is categorized under CWE-59: Improper Link Resolution Before File Access. This flaw is highly relevant in automated CI/CD architectures where third-party templates are executed with elevated build execution credentials. Successful exploitation yields unauthorized access to system configurations, keys, and credentials stored on the build container.

Root Cause Analysis

Hugo utilizes the afero library to construct virtual filesystem layers. In version v0.123.0, changes to path resolution modified the behavior of RootMappingFs.statRoot. Rather than using Lstat to examine files without dereferencing paths, the application invoked standard Stat operations.

Because Stat automatically resolves symbolic links, the filesystem driver evaluates the endpoint destination instead of the link container. This processing occurs prior to executing directory boundary checks. Consequently, files referencing absolute target paths escape the sandbox validation routine.

When a template invokes file-system commands like os.ReadFile, the root-mapping layer processes the input. The underlying file wrapper follows the malicious symbolic link and returns the content of the target file to the caller. This allows attackers to access any file on the underlying operating system that is readable by the compiling process.

Code-Level Deep Dive & Patch Analysis

The remediation introduced in version v0.163.1 contains two security adjustments. The primary fix in commit cf9c8f9 introduces DropSymlinksFs, a custom filesystem wrapper designed to intercept file execution requests and drop symbolic link operations.

// NewDropSymlinksFs returns an afero.Fs wrapper that treats symlinks as non-existing files.
func NewDropSymlinksFs(base afero.Fs) *DropSymlinksFs {
	return &DropSymlinksFs{base}
}
 
type DropSymlinksFs struct {
	afero.Fs
}
 
func (fs *DropSymlinksFs) Open(name string) (afero.File, error) {
	if _, err := fs.Stat(name); err != nil {
		return nil, err
	}
	return fs.Fs.Open(name)
}
 
func (fs *DropSymlinksFs) Stat(name string) (os.FileInfo, error) {
	fi, err := LstatIfPossible(fs.Fs, name)
	if err != nil {
		return nil, err
	}
	if fi.Mode()&os.ModeSymlink != 0 {
		return nil, os.ErrNotExist
	}
	return fi, nil
}

The Stat wrapper intercepts file access using LstatIfPossible. If the underlying mode indicates a symbolic link (fi.Mode()&os.ModeSymlink != 0), the wrapper returns os.ErrNotExist to simulate a missing file.

A secondary fix in commit a00b5c7 resolves an SSRF blocklist bypass vector. Previously, users could bypass IP blocks using decimal, hexadecimal, or octal IP configurations (e.g., http://2130706433/ for local addresses). The patch introduces host-name canonicalization before parsing blocklists:

func (c Config) CheckAllowedHTTPURL(u string) error {
	if !c.HTTP.URLs.Accept(u) {
		return deny(u)
	}
	if canon, ok := canonicalIPv4URL(u); ok && !c.HTTP.URLs.Accept(canon) {
		return deny(u)
	}
	return nil
}

This secondary canonicalization mitigates variations in URL encodings that previously bypassed target access validations.

Attack Methodology and Proof-of-Concept

To exploit this vulnerability, an attacker must have privileges to inject files into a repository compiled by Hugo. This commonly occurs when an attacker contributes a malicious theme or submits a pull request to a static site repository.

The attacker creates an absolute symbolic link within a theme directory referencing the target file:

ln -s /etc/passwd ./themes/malicious-theme/assets/exploit.txt

The attacker then adds an os.ReadFile call inside a layout template file (e.g., themes/malicious-theme/layouts/partials/header.html):

{{ if os.FileExists "themes/malicious-theme/assets/exploit.txt" }}
  <div class="output">
    {{ os.ReadFile "themes/malicious-theme/assets/exploit.txt" }}
  </div>
{{ end }}

During compilation, the Hugo template engine processes the layout commands. The virtual filesystem evaluates the symbolic link using Stat, resolving it to /etc/passwd. The engine reads the contents and appends them to the generated HTML output, making the data visible to the attacker.

Technical Impact and Threat Model

The security threat posed by this bypass is high for automated deployment platforms. Organizations running continuous delivery pipelines for static sites frequently process untrusted user templates. Compromise of a build pipeline via arbitrary file read can lead to complete server environment disclosure.

The CVSS v4 score is 6.0 (Medium Severity). The score reflects a local attack vector (AV:L) because file manipulation inside the repository is required to stage the symbolic link. However, the resulting subsequent confidentiality impact is high (SC:H) due to the exposure of files residing on the build environment.

If the build user runs with administrative privileges, an attacker can access system-level secrets. This includes cloud IAM metadata tokens, continuous integration deployment credentials, and host private SSH keys.

Remediation, Detection, and Defense-in-Depth

Organizations using Hugo should immediately upgrade to version v0.163.1 or higher. The update implements the DropSymlinksFs blocklist, which renders standard symbolic links harmless inside template lookups.

For systems where immediate upgrades are not possible, administrators can audit repositories for symbolic links. Run the following command inside target codebases:

find . -type l -ls

Additionally, isolate the static rendering process within unprivileged sandbox environments. Run build tasks under low-privilege accounts, and use container configurations that lack read access to critical host files. Restricting outbound network access on build nodes also limits potential data exfiltration vectors.

Official Patches

HugoOfficial Release v0.163.1

Technical Appendix

CVSS Score
6.0/ 10
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N

Affected Systems

Hugo Static Site Generator

Affected Versions Detail

Product
Affected Versions
Fixed Version
Hugo
gohugoio
>= v0.123.0, < v0.163.1v0.163.1
AttributeDetail
CWE IDCWE-59
Attack VectorLocal
CVSS v4 Score6.0
Exploit StatusPoC
ImpactArbitrary File Read
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1548Abuse Elevation Control Mechanism
Privilege Escalation
T1068Exploitation for Privilege Escalation
Privilege Escalation
CWE-59
Improper Link Resolution Before File Access ('Link Following')

The application attempts to access a file based on a filename, but it does not properly handle cases where that filename is a symbolic link pointing to a file outside the intended directory restriction.

Vulnerability Timeline

Vulnerability regression introduced in Hugo v0.123.0
2024-02-01
Patches committed to GitHub repository
2026-06-19
Hugo v0.163.1 released and security advisory published
2026-06-19

References & Sources

  • [1]GitHub Security Advisory GHSA-C3WQ-J5VH-68RC
  • [2]Hugo Security Advisory Directory

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•2 days ago•CVE-2026-58263
7.2

CVE-2026-58263: Mutation Cross-Site Scripting (mXSS) in Jodit Editor clean-html Sanitizer

CVE-2026-58263 is a high-severity Mutation Cross-Site Scripting (mXSS) vulnerability affecting Jodit Editor prior to version 4.12.28. The flaw exists in Jodit's built-in clean-html sanitizer plugin, which fails to securely parse and sanitize nested elements containing foreign namespaces like MathML and SVG. Attackers can bypass sanitization by smuggling malicious payload elements inside rawtext container tags like style inside a MathML node, leading to DOM mutation and unauthenticated arbitrary script execution in the context of the user's browser session.

Amit Schendel
Amit Schendel
10 views•6 min read
•2 days ago•CVE-2026-65841
5.3

CVE-2026-65841: Client-Side Cross-Site Scripting (XSS) via Foreign Namespace Sanitization Bypass in Jodit Editor

Jodit Editor versions prior to 4.13.6 are vulnerable to client-side Cross-Site Scripting (XSS). The clean-html plugin's sanitization routine performs case-sensitive lookups against uppercase-only element blacklists. When processing XML-based foreign namespaces such as SVG or MathML, DOM engines preserve the lowercase format of tags. Because Jodit's denyTags check fails to normalize tag casing, malicious script blocks nested inside foreign namespace elements completely bypass validation and serialize directly into the editor output.

Amit Schendel
Amit Schendel
7 views•6 min read
•2 days ago•CVE-2026-53510
8.1

CVE-2026-53510: Remote Code Execution via Dynamic WSDL Parsing in Savon Ruby SOAP Client

A critical code injection vulnerability exists in Savon, a widely used SOAP client library for Ruby, prior to version 2.17.2. The vulnerability resides within the Savon::Model.all_operations module, where operation names fetched from a target Web Services Description Language (WSDL) document are dynamically evaluated via module_eval without sanitization. An attacker capable of manipulating the target WSDL document (e.g., through Man-in-the-Middle attacks, DNS hijacking, or Server-Side Request Forgery) can execute arbitrary Ruby code in the context of the parent application process.

Alon Barad
Alon Barad
12 views•6 min read
•2 days ago•CVE-2026-53466
6.5

CVE-2026-53466: Integer Conversion Overflow in ImageMagick XCF Decoder

An integer conversion overflow vulnerability exists in the XCF decoder of ImageMagick before version 6.9.13-51 and 7.1.2-26. The issue arises from mixed-type arithmetic that promotes calculation results to floating-point representations, causing an undefined cast back to integer. Under optimizing compilers, this undefined behavior results in bounds checks being bypassed, allowing out-of-bounds heap reads.

Amit Schendel
Amit Schendel
6 views•6 min read
•2 days ago•CVE-2026-53599
7.5

CVE-2026-53599: Authenticated Remote Code Execution in REDAXO CMS via Mediapool File Upload Validation Bypass

An authenticated file upload validation bypass vulnerability exists in the REDAXO CMS Mediapool addon in versions 5.18.2 through 5.21.0. Under permissive web server configurations, this allows authenticated users with media upload privileges to achieve remote code execution via multi-segment extension file uploads.

Alon Barad
Alon Barad
9 views•7 min read
•2 days ago•CVE-2026-52887
10.0

CVE-2026-52887: Critical SQL Injection and Remote Code Execution in NocoBase

A critical SQL injection vulnerability exists in the @nocobase/plugin-notification-in-app-message plugin of NocoBase prior to version 2.0.61. The flaw is caused by direct string interpolation of user-controlled input into a Sequelize.literal() query, allowing authenticated users to execute stacked PostgreSQL queries and achieve remote code execution on the underlying database server.

Amit Schendel
Amit Schendel
14 views•7 min read