Node.js Permission Model Bypass in Hugo by GoHugoIO
CVE-2026-75926

9.3CRITICAL

Key Information:

Vendor

Gohugoio

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-75926?

A vulnerability in Hugo versions 0.162.0 to 0.164.x allows for arbitrary command execution through TailwindCSS. This occurs because TailwindCSS loading allows executing code within the Node process, bypassing intended file access restrictions. Specifically, the introduction of TailwindCSS into the permission model led to security gaps where an attacker could exploit default configurations to execute unauthorized commands. Hugo 0.165.0 addresses this issue by removing TailwindCSS from the default allow list.

Affected Version(s)

hugo 0.162.0 < 0.165.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Holmquist
.