{"schema_version":"1.7.5","id":"GO-2026-5740","published":"2026-07-24T18:35:55Z","modified":"2026-07-24T19:00:25.653470716Z","aliases":["CVE-2026-44301","GHSA-x597-9fr4-5857"],"summary":"Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo","details":"Hugo's Node tool execution allows file system access outside the project directory in github.com/gohugoio/hugo","affected":[{"package":{"name":"github.com/gohugoio/hugo","ecosystem":"Go","purl":"pkg:golang/github.com/gohugoio/hugo"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.161.0"}]}],"ecosystem_specific":{"custom_ranges":[{"events":[{"introduced":"0.43.0"}],"type":"ECOSYSTEM"}],"imports":[{"path":"github.com/gohugoio/hugo/config/security","symbols":["DecodeConfig"]},{"path":"github.com/gohugoio/hugo/common/hexec","symbols":["Exec.Npx","New"]},{"path":"github.com/gohugoio/hugo/resources/resource_transformers/babel","symbols":["DecodeOptions","New","babelTransformation.Transform"]},{"path":"github.com/gohugoio/hugo/common/hugo","symbols":["GetExecEnviron"]},{"path":"github.com/gohugoio/hugo/deps","symbols":["Deps.Clone","Deps.Init"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5740.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/gohugoio/hugo/security/advisories/GHSA-x597-9fr4-5857"},{"type":"FIX","url":"https://github.com/gohugoio/hugo/commit/a54c398b93821865547a9e21c73aad8a1d7f7bc1"}],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-5740"}}