Source: hugo
Version: 0.162.1-7
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for hugo.

CVE-2026-75926[0]:
| Hugo 0.161.0 placed the Node asset pipelines behind the Node.js
| permission model so that code running through PostCSS, Babel, or
| TailwindCSS could not reach the file system outside the project
| directory. Hugo 0.162.0 added tailwindcss to the AllowChildProcess
| default in config/security/securityConfig.go, which makes
| nodePermissionArgs in common/hexec/exec.go append --allow-child-
| process whenever the tool being launched is named tailwindcss.
| TailwindCSS loads the site's tailwind.config.js through require at
| startup, so top-level code in that file executes inside the
| permitted Node process and can call child_process to spawn a shell.
| The spawned process is not a Node process and inherits none of the
| permission flags, so it runs with the full privileges of the account
| performing the build. Building a site whose theme, module, or
| starter template supplies the Tailwind configuration therefore
| yields arbitrary command execution rather than the confined file
| access the permission model was introduced to enforce. Hugo 0.165.0
| removes tailwindcss from the default security.exec.allow list, so
| the tool is no longer launched under the default configuration.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-75926
    https://www.cve.org/CVERecord?id=CVE-2026-75926
[1] https://github.com/gohugoio/hugo/issues/15178
[2] https://github.com/gohugoio/hugo/issues/15171
[3] 
https://github.com/gohugoio/hugo/commit/8a55df7af2e6da31297245cc54fa2e3b521d93e8

Regards,
Salvatore

Reply via email to