{"id":"CVE-2026-50133","aliases":["GHSA-c54g-xjwj-8g82","GO-2026-5313"],"url":"https://o3.security/vulnerability/CVE-2026-50133","summary":"Hugo: XSS via text/html content files","details":"Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to the text/html media type (typically .html files under /content, or pages produced by a content adapter that sets content.mediaType = \"text/html\") had their body emitted verbatim into the rendered page. A site that ingests HTML content from an untrusted source could therefore be served stored cross-site scripting. This vulnerability is fixed in 0.162.0.","published":"2026-07-06T19:31:18.386Z","modified":"2026-08-12T03:51:39.620964436Z","cvss":null,"epss":{"score":0.00327,"percentile":0.25237,"asOf":"2026-09-01"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/gohugoio/hugo","fixedVersion":"0.162.0"}],"fix":{"url":"https://github.com/gohugoio/hugo/commit/e41a06447daa3071a01f333fdcec0a5153c3c8d1","label":"gohugoio/hugo@e41a064"},"references":[{"type":"WEB","url":"https://github.com/gohugoio/hugo/releases/tag/v0.162.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50133.json"},{"type":"ADVISORY","url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-c54g-xjwj-8g82"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50133"},{"type":"FIX","url":"https://github.com/gohugoio/hugo/commit/e41a06447daa3071a01f333fdcec0a5153c3c8d1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:39.620964436Z"}}