CVE-2026-100691 | gohugoio Hugo up to 0.165.x Syntax Highlighter lineAnchors cross site scripting
A vulnerability classified as problematic was found in gohugoio Hugo up to 0.165.x. This vulnerability affects unknown code of the component Syntax Highlighter. Such manipulation of the argument lineAnchors leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-100691. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More