CVE-2026-35166: Hugo does not properly escape some Markdown links

Published Apr 3, 2026
·
Updated

Impact Links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected.

Patches Patched in v0.159.2

Workarounds Create custom render hooks for links and images in a Hugo theme/project.

Other sources

Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected. This vulnerability is fixed in 0.159.2.

MITRE

Affected Software

4 affected componentsFixes available
go/github.com/gohugoio/hugo>=0.60.0<0.159.2
0.159.2
gohugo Hugo Linux>=0.60.0<0.159.2
gohugo Hugo Macos>=0.60.0<0.159.2
gohugo Hugo Windows>=0.60.0<0.159.2

Event History

Apr 3, 2026
Advisory Published
via GitHub·11:38 PM
Data Sourced
via GitHub·11:38 PM
DescriptionWeaknessAffected Software
Apr 6, 2026
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
Affected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203