CVE-2026-100690 | gohugoio Hugo up to 0.165.x Symbolic Link assets/css/x.css path traversal

SecurityVulns

A vulnerability was found in gohugoio Hugo up to 0.165.x. It has been rated as problematic. The impacted element is an unknown function of the file assets/css/x.css of the component Symbolic Link Handler. This manipulation causes path traversal.

This vulnerability is registered as CVE-2026-100690. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More