CVE-2026-100691 | gohugoio Hugo up to 0.165.x Syntax Highlighter lineAnchors cross site scripting

SecurityVulns

A vulnerability classified as problematic was found in gohugoio Hugo up to 0.165.x. This vulnerability affects unknown code of the component Syntax Highlighter. Such manipulation of the argument lineAnchors leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-100691. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is advised.VulDB Recent EntriesRead More