#1144973 hugo: CVE-2026-75926

Package:
src:hugo
Source:
src:hugo
Submitter:
Salvatore Bonaccorso
Date:
2026-08-21 04:07:02 UTC
Severity:
normal
Tags:
#1144973#5
Date:
2026-08-21 04:05:09 UTC
From:
To:
Hi,

The following vulnerability was published for hugo.

CVE-2026-75926[0]:
| Hugo 0.161.0 placed the Node asset pipelines behind the Node.js
| permission model so that code running through PostCSS, Babel, or
| TailwindCSS could not reach the file system outside the project
| directory. Hugo 0.162.0 added tailwindcss to the AllowChildProcess
| default in config/security/securityConfig.go, which makes
| nodePermissionArgs in common/hexec/exec.go append --allow-child-
| process whenever the tool being launched is named tailwindcss.
| TailwindCSS loads the site's tailwind.config.js through require at
| startup, so top-level code in that file executes inside the
| permitted Node process and can call child_process to spawn a shell.
| The spawned process is not a Node process and inherits none of the
| permission flags, so it runs with the full privileges of the account
| performing the build. Building a site whose theme, module, or
| starter template supplies the Tailwind configuration therefore
| yields arbitrary command execution rather than the confined file
| access the permission model was introduced to enforce. Hugo 0.165.0
| removes tailwindcss from the default security.exec.allow list, so
| the tool is no longer launched under the default configuration.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-75926
https://www.cve.org/CVERecord?id=CVE-2026-75926
[1] https://github.com/gohugoio/hugo/issues/15178
[2] https://github.com/gohugoio/hugo/issues/15171
[3] https://github.com/gohugoio/hugo/commit/8a55df7af2e6da31297245cc54fa2e3b521d93e8

Regards,
Salvatore