GHSA-8j34-9876-pvfq

    Dashboard / Vulnerabilities / GHSA-8j34-9876-pvfq

    GHSA-8j34-9876-pvfq

    Published: 23 Jun 2021Last Modified: 10 Sept 2026

    Summary: Hugo can execute a binary from the current directory on Windows

    Details: ## Impact Hugo depends on Go's `os/exec` for certain features, e.g. for rendering of Pandoc documents if these binaries are found in the system `%PATH%` on Windows. However, if a malicious file with the same name (`exe` or `bat`) is found in the current working directory at the time of running `hugo`, the malicious command will be invoked instead of the system one. Windows users who run `hugo` inside untrusted Hugo sites are affected. ## Patches Users should upgrade to Hugo v0.79.1.

    Affected packages

    Package

    Name: github.com/gohugoio/hugo

    Purl: pkg:golang/github.com/gohugoio/hugo

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.79.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-8j34-9876-pvfq | CVE-DB