Hi, The following vulnerability was published for hugo. CVE-2026-75926[0]: | Hugo 0.161.0 placed the Node asset pipelines behind the Node.js | permission model so that code running through PostCSS, Babel, or | TailwindCSS could not reach the file system outside the project | directory. Hugo 0.162.0 added tailwindcss to the AllowChildProcess | default in config/security/securityConfig.go, which makes | nodePermissionArgs in common/hexec/exec.go append --allow-child- | process whenever the tool being launched is named tailwindcss. | TailwindCSS loads the site's tailwind.config.js through require at | startup, so top-level code in that file executes inside the | permitted Node process and can call child_process to spawn a shell. | The spawned process is not a Node process and inherits none of the | permission flags, so it runs with the full privileges of the account | performing the build. Building a site whose theme, module, or | starter template supplies the Tailwind configuration therefore | yields arbitrary command execution rather than the confined file | access the permission model was introduced to enforce. Hugo 0.165.0 | removes tailwindcss from the default security.exec.allow list, so | the tool is no longer launched under the default configuration. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-75926 https://www.cve.org/CVERecord?id=CVE-2026-75926 [1] https://github.com/gohugoio/hugo/issues/15178 [2] https://github.com/gohugoio/hugo/issues/15171 [3] https://github.com/gohugoio/hugo/commit/8a55df7af2e6da31297245cc54fa2e3b521d93e8 Regards, Salvatore