CVE-2026-10618 | gohugoio Hugo up to 0.165.0 Fenced-Code-Block Renderer attributes.go RenderAttributes cross site scripting

SecurityVulns

A vulnerability classified as problematic has been found in gohugoio Hugo up to 0.165.0. This vulnerability affects the function RenderAttributes of the file markup/internal/attributes/attributes.go of the component Fenced-Code-Block Renderer. Performing a manipulation results in cross site scripting.

This vulnerability is reported as CVE-2026-10618. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More