Node.js Permission Model Bypass in Hugo by GoHugoIO
CVE-2026-75926
9.3CRITICAL
What is CVE-2026-75926?
A vulnerability in Hugo versions 0.162.0 to 0.164.x allows for arbitrary command execution through TailwindCSS. This occurs because TailwindCSS loading allows executing code within the Node process, bypassing intended file access restrictions. Specifically, the introduction of TailwindCSS into the permission model led to security gaps where an attacker could exploit default configurations to execute unauthorized commands. Hugo 0.165.0 addresses this issue by removing TailwindCSS from the default allow list.
Affected Version(s)
hugo 0.162.0 < 0.165.0
