CVE-2024-32875

MEDIUM

Hugo 0.123.0-0.125.2 - Cross-Site Scripting in Markdown Title Arguments

Title source: llm
STIX 2.1

Description

Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown for links and images not escaped in internal render hooks. Hugo users who are impacted are those who have these hooks enabled and do not trust their Markdown content files. The issue is patched in v0.125.3. As a workaround, replace the templates with user defined templates or disable the internal templates.

References (3)

Core 3

Scores

CVSS v3 6.1
EPSS 0.0054
EPSS Percentile 40.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79 CWE-80
Status published
Products (2)
gohugoio/hugo 0.123.0 - 0.125.3Go
gohugoio/hugo >= 0.123.0, < 0.125.3
Published Apr 23, 2024
Tracked Since Feb 18, 2026