CVE-2026-89259 | gohugoio Hugo up to 0.164.x Build Process hugo.toml permission

SecurityVulns

A vulnerability was found in gohugoio Hugo up to 0.164.x. It has been declared as critical. This impacts an unknown function of the file hugo.toml of the component Build Process. Such manipulation leads to permission issues.

This vulnerability is uniquely identified as CVE-2026-89259. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More