CVE-2026-35166: Hugo does not properly escape some Markdown links
Published Apr 3, 2026
·Updated
Impact Links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected.
Patches Patched in v0.159.2
Workarounds Create custom render hooks for links and images in a Hugo theme/project.
Other sources
Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected. This vulnerability is fixed in 0.159.2.
— MITRE
Affected Software
4 affected componentsFixes available
go/github.com/gohugoio/hugo>=0.60.0<0.159.2
0.159.2
gohugo Hugo Linux>=0.60.0<0.159.2
gohugo Hugo Macos>=0.60.0<0.159.2
gohugo Hugo Windows>=0.60.0<0.159.2
Event History
Apr 3, 2026
Advisory Published
via GitHub·11:38 PM
Data Sourced
via GitHub·11:38 PM
DescriptionWeaknessAffected Software
Apr 6, 2026
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
Affected Software