CVE-2026-58402EPSS p20.7%
CVE-2026-58402CVE-2026-58402
gohugo / hugo
Description
Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string into the code class="language-…" data-lang="…" wrapper without HTML escaping. A fence info-string containing a quote and a script payload breaks out of the attribute and injects a live script element. This issue is fixed in 0.163.3.
Scoring
| CVSS | 5.4 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 0.30% probability of exploitation · percentile 20.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-08 |